Erident Custom Login and Dashboard <= 3.5.8 - Authenticated Stored Cross-Site Scripting
2021-04-01 00:00
James CalverStrategic Overview
StatusPatched in 3.5.9
Affected PluginErident Custom Login and Dashboard
Affected Version
<= 3.5.8CVSS4.8Medium
CVE
CVE-2021-24658Vulnerability Overview
The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)
Technical Analysis
REMEDIATION: Update to version 3.5.9, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C