CVE-2021-36884: WordPress Backup Migration plugin <= 1.1.5 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
Published Nov 19, 2021
·Updated
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1.5 versions.
Affected Software
1 affected component
BackupBliss Backup Migration Wordpress<=1.1.5
Remediation
Information
Update to 1.1.6 or higher version.
Event History
Nov 19, 2021
CVE Published
via MITRE·06:19 PM
Data Sourced
via MITRE·06:19 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-36884?
CVE-2021-36884 is an Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin version 1.1.5 and below.
2
How severe is CVE-2021-36884?
CVE-2021-36884 has a severity level of 5.4 (Medium).
3
Which software versions are affected by CVE-2021-36884?
WordPress Backup Migration plugin versions up to and including 1.1.5 are affected by CVE-2021-36884.
4
How can I fix CVE-2021-36884?
To fix CVE-2021-36884, it is recommended to update the WordPress Backup Migration plugin to a version higher than 1.1.5.
5
Where can I find more information about CVE-2021-36884?
You can find more information about CVE-2021-36884 on the Patchstack Vulnerability Database and the WordPress Backup Migration plugin developer page.