CVE Database /
CVE-2021-24992
CVE · Medium
CVE-2021-24992 — Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder [buttonizer-multifunctional-button] < 2.6.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24992
|
Buttonizer – Floating Menus, Sticky Buttons, & Popup Builder [buttonizer-multifunctional-button] < 2.6.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 2.6.3
|
2.6.3 |
2021-11-29 |
—
|
CVE-2021-24992
The Buttonizer plugin versions before 2.6.3 failed to properly filter and escape certain parameters that were displayed in HTML attributes and page content. This oversight allowed authenticated users with elevated privileges to inject and execute malicious scripts, bypassing security restrictions that normally prevent unfiltered HTML content from being processed. The vulnerability could be exploited even when administrators had disabled the unfiltered_html capability for user roles.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings