CVE-2021-24826

CVE-2021-24826: Custom Content Shortcode < 4.0.2 - Authenticated Stored Cross-Site Scripting

Vendor Unknown
Product Custom Content Shortcode
Weakness CWE-79 · XSS
Published March 7, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which could allow Contributor+ (v < 4.0.1) or Admin+ (v < 4.0.2) users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. Please note that such attack is still possible by admin+ in single site blogs by default (but won't be when the unfiltered_html is disallowed)

Key dates

02Disclosure timeline

March 7, 2022 CVE published
August 3, 2024 Record updated