Record summary

CVE-2021-24444 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

TaxoPress – Create and Manage Taxonomies, Tags, Categories

CVE List3.0.7.2 to < 3.0.7.2affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated)ExploitDB exploitby Akash PatilNot analyzed1 file
ExploitDB

PoC details

References

3