CVE-2021-24488 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 11.2% (pctl 96)
Patch early
A public exploit exists.
Description
The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 11.24% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-08-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| pickplugins | post grid |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS) | 2022-02-02 |
References
→ the Explorer · watch your stack · NVD