plugin

Keyword Meta Vulnerabilities

1 known security issue reported for the Keyword Meta WordPress plugin. Most recent disclosed Aug 9, 2021.

1 medium

Running Keyword Meta on your site? Check whether your installed version is affected.

Scan your site free

Keyword Meta <= 3.0 - Cross-Site Scripting

medium

The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing attacker to make a logged in high privilege user save arbitrary setting...

CVSS:
6.1
Affected:
up to 3.0
Fixed in:
3.1
Disclosed:
Aug 9, 2021

CVE-2021-24611 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database