CVE-2021-4252 Information

Description

A vulnerability which was classified as problematic has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER[\HTTP_USER_AGENT] leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76. It is recommended to apply a patch to fix this issue. The identifier VDB-216209 was assigned to this vulnerability.

Reference

https://vuldb.com/?id.216209 https://github.com/lesterchan/wp-ban/commit/13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76 https://github.com/lesterchan/wp-ban/pull/11

Share on: