Cross-Site Scripting in WordPress Popular Posts Plugin by WordPress
CVE-2021-20746
5.4MEDIUM
What is CVE-2021-20746?
The WordPress Popular Posts plugin prior to version 5.3.2 is susceptible to a cross-site scripting (XSS) vulnerability. This allows remote authenticated attackers to inject arbitrary web scripts into the application through unspecified vectors, potentially compromising sensitive user information or leading to further exploitation of the website. Website administrators are advised to upgrade to the latest version of the plugin to mitigate these risks.
Affected Version(s)
WordPress Popular Posts 5.3.2 and earlier