Vulnerabilities > CVE-2021-24485 - Unspecified vulnerability in Wp-Special-Textboxes Project Wp-Special-Textboxes

047910
CVSS 4.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
wp-special-textboxes-project

Summary

The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

Vulnerable Configurations

Part Description Count
Application
Wp-Special-Textboxes_Project
53