First published: Tue Apr 26 2022(Updated: )
Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG image upload.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tripetto Tripetto | <=5.1.4 |
Update to 5.2.0 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36895 has a medium severity rating due to its potential for allowing unauthenticated cross-site scripting attacks.
To fix CVE-2021-36895, upgrade the Tripetto plugin to version 5.1.5 or later.
CVE-2021-36895 is an unauthenticated Cross-Site Scripting (XSS) vulnerability.
CVE-2021-36895 exploits the ability to upload untrusted SVG images, which can contain malicious scripts.
CVE-2021-36895 affects the Tripetto plugin for WordPress versions up to and including 5.1.4.