The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2021-07-19T10:53:15
Updated: 2024-08-03T19:28:24.018Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24436
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-07-19T11:15:08.403
Modified: 2024-11-21T05:53:04.217
Link: CVE-2021-24436
Redhat
No data.