8.8
CVSSv3

CVE-2021-24581

Published: 30/08/2021 Updated: 11/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Blue Admin WordPress plugin up to and including 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

blue-admin project blue-admin

Exploits

WordPress Blue Admin plugin version 210601 suffers from a cross site request forgery vulnerability ...