Vulnerabilities > CVE-2021-24899 - Unspecified vulnerability in Media-Tags Project Media-Tags
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |