peter bassill · operator
$ cve CVE-2021-24444 JSON

CVE-2021-24444 EXPLOIT

4.8
MEDIUM · CVSS 3.1 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.

Scoring

CVSS4.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS2.32% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-08-02
Last modified2026-06-17

Affected (1)

VendorProduct
taxopresstaxopress

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD