CVE Database /
CVE-2021-24444
CVE · Medium
CVE-2021-24444 — Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24444
|
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 3.0.7.2
|
3.0.7.2 |
2021-06-30 |
—
|
CVE-2021-24444
The TaxoPress plugin versions prior to 3.0.7.2 contain a stored cross-site scripting vulnerability in the taxonomy description field. Administrators and other high-privilege users can inject malicious JavaScript code into taxonomy descriptions, bypassing restrictions on the unfiltered_html capability due to improper input sanitization. This vulnerability allows attackers with elevated permissions to execute arbitrary scripts that persist in the database and affect other users viewing the affected taxonomies.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings