Any Hostname [any-hostname] <= 1.0.6 (unfixed + closed)
unknown
[en] The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 2, 2021
CVE-2021-24481 on NVD →
Any Hostname <= 1.0.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an authenticated stored XSS issue as high privilege users are able to set XSS payloads in it
- CVSS:
- 5.5
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 28, 2021
CVE-2021-24481 on NVD →
Any Hostname [any-hostname] <= 1.0.6 (unfixed + closed)
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by ABISHEIK M in WordPress Any Hostname plugin (versions <= 1.0.6).
- Affected:
- up to 1.0.6
- Fix:
- No patched version reported
- Disclosed:
- Jun 28, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database