First published: Fri Nov 26 2021(Updated: )
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee).
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Awesome Support | <=6.0.6 |
Update to 6.0.7 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36919 is a vulnerability known as Multiple Authenticated Reflected Cross-Site Scripting (XSS) in the WordPress Awesome Support plugin.
The severity of CVE-2021-36919 is medium with a CVSS score of 5.4.
Versions up to and including 6.0.6 of the WordPress Awesome Support plugin are affected by CVE-2021-36919.
The Common Weakness Enumeration (CWE) ID associated with CVE-2021-36919 is CWE-79.
Yes, you can find more information about CVE-2021-36919 and possible solutions in the following references: [link1](https://patchstack.com/database/vulnerability/awesome-support/wordpress-awesome-support-plugin-6-0-6-multiple-authenticated-reflected-cross-site-scripting-xss-vulnerabilities) and [link2](https://wordpress.org/plugins/awesome-support/#developers).