peter bassill · operator
$ cve CVE-2021-24287 JSON

CVE-2021-24287 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 10.4% (pctl 96)

Patch early

A public exploit exists.

Description

The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS10.36% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-05-14
Last modified2026-06-17

Affected (1)

VendorProduct
mooveagencyselect all categories and taxonomies\, change checkbox to radio buttons

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD