WP Customer Reviews < 3.5.6 - Authenticated Stored Cross-Site Scripting (XSS)
Vulnerability Description
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24296
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Truoc Phan from Techlab Corporation
Affected Vendor
Go Web Solutions
View all reports →