plugin

Language Bar Flags Vulnerabilities

1 known security issue reported for the Language Bar Flags WordPress plugin. Most recent disclosed Aug 16, 2021.

1 medium

Running Language Bar Flags on your site? Check whether your installed version is affected.

Scan your site free

Language Bar Flags <= 1.0.8 - Cross-Site Request Forgery leading to Stored Cross-Site Scripting

medium

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which w...

CVSS:
6.1
Affected:
up to 1.0.8
Fixed in:
1.1.0
Disclosed:
Aug 16, 2021

CVE-2021-24431 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database