WP HTML Author Bio [wp-html-author-bio-by-ahmad-awais] <= 1.2.0 (unfixed + closed)
unknown
[en] The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Sc...
- Affected:
- up to 1.2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2021
CVE-2021-24545 on NVD →
WP HTML Author Bio <= 1.2.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripti...
- CVSS:
- 5.4
- Affected:
- up to 1.2.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 21, 2021
CVE-2021-24545 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database