CVE-2021-24574

Severity
4.8MEDIUM
EPSS
0.2%
top 57.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 23
Latest updateMay 24

Description

The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/simple_banner2.10.42.10.4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jx5c-5jv3-g74m: The Simple Banner WordPress plugin before 22022-05-24
CVEList
Simple Banner < 2.10.4 - Authenticated Stored XSS2021-08-23
CVE-2021-24574 (MEDIUM CVSS 4.8) | The Simple Banner WordPress plugin | cvebase.io