SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24134

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary…

MEDIUM 4.8EPSS 0.65%

Does this matter?

Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.

Description

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.65% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
constantcontact/constant contact forms
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.