CVE · Medium

CVE-2021-24533 — Maintenance [maintenance] < 4.03

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24533 Maintenance [maintenance] < 4.03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.03 4.03 2021-07-21

CVE-2021-24533

The Maintenance plugin before version 4.03 fails to properly sanitize or escape certain configuration settings, enabling administrators and other high-privilege users to inject Cross-Site Scripting attacks through these settings that execute on the front-end, even when unfiltered HTML capabilities are restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.