Per Page Add To Head <= 1.4.3 Cross-Site Request Forgery to Stored Cross-Site Scripting
high
The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin), this could lead to Stored...
- CVSS:
- 8.8
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Aug 11, 2021
CVE-2021-24586 on NVD →
Per Page Add to Head <= 1.4.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
- CVSS:
- 4.8
- Affected:
- up to 1.4.4
- Fix:
- No patched version reported
- Disclosed:
- Aug 11, 2021
CVE-2021-24619 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database