The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-07-12T19:20:58

Updated: 2024-08-03T19:28:23.956Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-12T20:15:09.337

Modified: 2024-11-21T05:53:03.060

Link: CVE-2021-24427

cve-icon Redhat

No data.