peter bassill · operator
$ cve CVE-2021-24488 JSON

CVE-2021-24488 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 11.2% (pctl 96)

Patch early

A public exploit exists.

Description

The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not properly sanitised before being output back in the pages, leading to Reflected Cross-Site Scripting issues

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS11.24% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-08-02
Last modified2026-06-17

Affected (1)

VendorProduct
pickpluginspost grid

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD