CVE-2021-24332

Severity
4.8MEDIUM
EPSS
0.2%
top 59.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 24

Description

The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/autoptimize2.8.42.8.4

🔴Vulnerability Details

2
GHSA
GHSA-5fgw-wpxm-vqq2: The Autoptimize WordPress plugin before 22022-05-24
CVEList
Autoptimize < 2.8.4 - Authenticated Stored Cross-Site Scripting (XSS)2021-05-24
CVE-2021-24332 (MEDIUM CVSS 4.8) | The Autoptimize WordPress plugin be | cvebase.io