CVE Feed

    Dashboard / CVE / CVE-2021-24618

    CVE-2021-24618

    The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.

    Published:Sep 20, 2021
    Last Modified:Nov 21, 2024
    EPS:Sep 20, 2021
    EPSS Score:0.00271
    CVSS Score:5.4

    Affected Products

    Vendor
    Wbolt
    Product
    Donate With Qrcode

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High