CVE-2021-24444 EXPLOIT
4.8
MEDIUM · CVSS 3.1 · EPSS 2.3% (pctl 83)
Patch early
A public exploit exists.
Description
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.
Scoring
| CVSS | 4.8 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 2.32% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-08-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| taxopress | taxopress |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin TaxoPress 3.0.7.1 - Stored Cross-Site Scripting (XSS) (Authenticated) | 2021-10-25 |
References
- http://packetstormsecurity.com/files/164604/WordPress-TaxoPress-3.0.7.1-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/a31321fe-adc6-4480-a220-35aedca52b8b
- http://packetstormsecurity.com/files/164604/WordPress-TaxoPress-3.0.7.1-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/a31321fe-adc6-4480-a220-35aedca52b8b
→ the Explorer · watch your stack · NVD