CVE Database /
CVE-2021-24427
CVE · Medium
CVE-2021-24427 — W3 Total Cache [w3-total-cache] < 2.1.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24427
|
W3 Total Cache [w3-total-cache] < 2.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 2.1.3
|
2.1.3 |
2021-04-25 |
—
|
CVE-2021-24427
The W3 Total Cache plugin contains a stored cross-site scripting vulnerability in versions through 2.1.2 affecting multiple CDN configuration options. Administrators on multisite WordPress installations or those with unfiltered_html disabled could inject malicious scripts through inadequately sanitized inputs that fail to be properly escaped on output. These injected scripts would then execute for any user viewing affected pages. The vulnerability was remedied in version 2.1.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings