CVE · Medium

CVE-2021-24685 — Flat Preloader [flat-preloader] < 1.5.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24685 Flat Preloader [flat-preloader] < 1.5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.4 1.5.4 2021-09-28

CVE-2021-24685

The Flat Preloader plugin before version 1.5.4 fails to implement nonce verification when administrators save settings, and inadequately sanitizes and escapes the stored values. This vulnerability permits attackers to execute cross-site request forgery attacks against logged-in administrators, injecting malicious scripts that execute either on the frontend or backend depending on the payload used. While version 1.5.1 addressed the CSRF issue, additional sanitization improvements were necessary through versions 1.5.2 to 1.5.4 to fully resolve the vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.