CVE · Medium

CVE-2021-24427 — W3 Total Cache [w3-total-cache] < 2.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24427 W3 Total Cache [w3-total-cache] < 2.1.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.1.3 2.1.3 2021-04-25

CVE-2021-24427

The W3 Total Cache plugin contains a stored cross-site scripting vulnerability in versions through 2.1.2 affecting multiple CDN configuration options. Administrators on multisite WordPress installations or those with unfiltered_html disabled could inject malicious scripts through inadequately sanitized inputs that fail to be properly escaped on output. These injected scripts would then execute for any user viewing affected pages. The vulnerability was remedied in version 2.1.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.