plugin

Site Audit Vulnerabilities

2 known security issues reported for the Site Audit WordPress plugin. Most recent disclosed Aug 16, 2021.

1 medium

Running Site Audit on your site? Check whether your installed version is affected.

Scan your site free

My Site Audit [site-audit] < 1.2.5 (closed)

unknown

[en] The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 16, 2021

CVE-2021-24445 on NVD →

My Site Audit <= 1.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.

CVSS:
5.5
Affected:
up to 1.2.4
Fixed in:
1.2.5
Disclosed:
Jul 19, 2021

CVE-2021-24445 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database