5.4
CVSSv3

CVE-2021-24611

Published: 06/09/2021 Updated: 13/09/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Keyword Meta WordPress plugin up to and including 3.0 does not sanitise of escape its settings before outputting them back in the page after they are saved, allowing for Cross-Site Scripting issues. Furthermore, it is also lacking any CSRF check, allowing malicious user to make a logged in high privilege user save arbitrary setting via a CSRF attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

keyword meta project keyword meta