VulnerabilityModified
CVE-2021-24883
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
MEDIUM 5.4EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- essentialplugin/popup anything
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2610975Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/c5dd3812-ea20-4e05-a5d3-84830b452822Third Party Advisory
- https://www.fortiguard.com/zeroday/FG-VD-21-069Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2610975Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/c5dd3812-ea20-4e05-a5d3-84830b452822Third Party Advisory
- https://www.fortiguard.com/zeroday/FG-VD-21-069Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.