SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24533

The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be…

MEDIUM 4.8EPSS 0.62%

Does this matter?

Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.

Description

The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.62% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
webfactoryltd/maintenance
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.