CVE · Medium

CVE-2021-24564 — WPFront Scroll Top [wpfront-scroll-top] < 2.0.6.07225

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24564 WPFront Scroll Top [wpfront-scroll-top] < 2.0.6.07225 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.0.6.07225 2.0.6.07225 2021-07-26

CVE-2021-24564

The WPFront Scroll Top plugin before version 2.0.6.07225 contains an authenticated stored cross-site scripting vulnerability in its Image ALT setting. The plugin fails to properly sanitize or escape this setting before rendering it in HTML attributes, allowing authenticated users to inject malicious scripts even when the unfiltered_html capability is restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.