CVE-2021-24586 Information
Jun 07, 2022
cve
Description
The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings which could allow attackers to make a logged in admin change them. Furthermore as the plugin allows arbitrary HTML to be inserted in one of the setting (feature mentioned by the plugin) this could lead to Stored XSS issue which will be triggered either in the backend frontend or both depending on the payload used.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Reference
https://wpscan.com/vulnerability/e9885fba-0e73-41a0-9e1d-47badc09be85
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: