VulnerabilityModified
CVE-2021-24241
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
MEDIUM 6.1EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
The Advanced Custom Fields Pro WordPress plugin before 5.9.1 did not properly escape the generated update URL when outputting it in an attribute, leading to a reflected Cross-Site Scripting issue in the update settings page.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- advancedcustomfields/advanced custom fields
- Source
- contact@wpscan.com
References
- https://github.com/jdordonezn/Reflected-XSS-in-WordPress-for-ACF-PRO-before-5.9.1-plugin/issues/1Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/d1e9c995-37bd-4952-b88e-945e02e3c83fExploit, Third Party Advisory
- https://www.advancedcustomfields.com/blog/acf-5-9-1-release/Release Notes, Vendor Advisory
- https://github.com/jdordonezn/Reflected-XSS-in-WordPress-for-ACF-PRO-before-5.9.1-plugin/issues/1Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/d1e9c995-37bd-4952-b88e-945e02e3c83fExploit, Third Party Advisory
- https://www.advancedcustomfields.com/blog/acf-5-9-1-release/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.