m0ze.ru
https://m0ze.ru/vulnerability/%5B2021-04-25%5D-%5BWordPress%5D-%5BCWE-79%5D-W3-Total-Cache-WordPress-Plugin-v2.1.2.txt CVE-2021-24427
MEDIUM
W3 Total Cache < 2.1.3 - Authenticated Stored XSS
Record summary
CVE-2021-24427 has a selected CVSS score of 4.8 (medium).
Description
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
W3 Total CacheBrowse BoldGrid / W3 Total Cache | CVE List | 2.1.3 to < 2.1.3 | affected |
References
4m0ze.ru
https://m0ze.ru/vulnerability/[2021-04-25]-[WordPress]-[CWE-79]-W3-Total-Cache-WordPress-Plugin-v2.1.2.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24427 wpscan.comConfirmation
https://wpscan.com/vulnerability/5da5ce9a-82a6-404f-8dec-795d7905b3f9