CVE-2021-24611
MEDIUMKeyword Meta < 3.0 - Cross-Site Scripting and Cross-Site Request Forgery
Title source: llmDescription
The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting via a CSRF attack.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/b4a2e595-6971-4a2a-a346-ac4445a5e0cd
Scores
CVSS v3
5.4
EPSS
0.0032
EPSS Percentile
23.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-352
CWE-79
Status
published
Products (1)
keyword_meta_project/keyword_meta
< 3.0
Published
Sep 06, 2021
Tracked Since
Feb 18, 2026