VulnerabilityModified
CVE-2021-24642
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them.
MEDIUM 6.5EPSS 0.57%
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-352
- Affected
- scroll banner project/scroll banner
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/8d9129ab-33c3-44ee-b150-f7552d88e658Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/8d9129ab-33c3-44ee-b150-f7552d88e658Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.