Cross-Site Scripting in WordPress Popular Posts Plugin by WordPress
CVE-2021-20746

5.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
28 June 2021

Summary

The WordPress Popular Posts plugin prior to version 5.3.2 is susceptible to a cross-site scripting (XSS) vulnerability. This allows remote authenticated attackers to inject arbitrary web scripts into the application through unspecified vectors, potentially compromising sensitive user information or leading to further exploitation of the website. Website administrators are advised to upgrade to the latest version of the plugin to mitigate these risks.

Affected Version(s)

WordPress Popular Posts 5.3.2 and earlier

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.