RSS for Yandex Turbo < 1.30 - Authenticated Stored Cross-Site Scripting (XSS)
Vulnerability Description
The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24277
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Himamshu Dilip Kulkarni
Affected Vendor
Flector
View all reports →