CVE · Medium

CVE-2021-25050 — Remove Footer Credit [remove-footer-credit] < 1.0.11

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-25050 Remove Footer Credit [remove-footer-credit] < 1.0.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.0.11 1.0.11 2022-01-11

CVE-2021-25050

The Remove Footer Credit plugin in versions prior to 1.0.11 fails to adequately sanitize its configuration options, enabling administrators and other high-privilege users to inject malicious scripts even in environments where unfiltered_html capabilities are restricted. This Cross-Site Scripting vulnerability could allow privileged attackers to execute arbitrary JavaScript code within the WordPress admin interface or frontend.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.