CVE-2021-24626
Dashboard / Vulnerabilities / CVE-2021-24626
CVE-2021-24626
Published: 8 Nov 2021Last Modified: 10 Mar 2026
Summary:
Details: The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape the css_id POST parameter before using it in a SQL statement, leading to a SQL Injection
References: , https://codevigilant.com/disclosure/2021/wp-plugin-chameleon-css/, https://wpscan.com/vulnerability/06cb6c14-99b8-45b6-be2e-f4dcca8a4165
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
