6.1
CVSSv3

CVE-2021-24452

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: 4.3 | VMScore: 710 | EPSS: 0.09774 | KEV: Not Included
Published: 19/07/2021 Updated: 21/11/2024

Vulnerability Summary

The W3 Total Cache WordPress plugin prior to 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

boldgrid w3 total cache