5.4
CVSSv3

CVE-2021-24365

Published: 12/07/2021 Updated: 15/07/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Admin Columns WordPress plugin Free prior to 4.3.2 and Pro prior to 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

admincolumns admin columns

Exploits

WordPress Admin Columns plugin versions below 552 Pro and 432 Pro suffers from a cross site scripting vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SYSS-2021-032 Admin Columns WordPress Plug-In - Persistent Cross-Site Scripting <!--X-Subject-Header-End--> <!--X-Head ...