CVE Database /
CVE-2021-24218
CVE · High
CVE-2021-24218 — Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24218
|
Meta pixel for WordPress [official-facebook-pixel] >= 3.0.0 - <= 3.0.3 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
3.0.0–3.0.4
|
3.0.4 |
2021-03-25 |
—
|
CVE-2021-24218
The Facebook for WordPress plugin versions 3.0.0 through 3.0.3 contained a cross-site request forgery vulnerability in the wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions because they did not implement nonce verification. Additionally, the saveFbeSettings function failed to sanitize input, permitting attackers to inject and store script tags within the plugin settings. These flaws were resolved in version 3.0.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings