My Site Audit [site-audit] < 1.2.5 (closed)
unknown
[en] The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Aug 16, 2021
CVE-2021-24445 on NVD →
My Site Audit <= 1.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.
- CVSS:
- 5.5
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.5
- Disclosed:
- Jul 19, 2021
CVE-2021-24445 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database