CVE-2021-24685
The Flat Preloader plugin before version 1.5.4 fails to implement nonce verification when administrators save settings, and inadequately sanitizes and escapes the stored values. This vulnerability permits attackers to execute cross-site request forgery attacks against logged-in administrators, injecting malicious scripts that execute either on the frontend or backend depending on the payload used. While version 1.5.1 addressed the CSRF issue, additional sanitization improvements were necessary through versions 1.5.2 to 1.5.4 to fully resolve the vulnerability.
Based on public CVE data (MITRE/NVD).