CVE-2021-24654

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
04/10/2021
Last modified:
08/10/2021

Description

The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpeverest:user_registration:*:*:*:*:*:wordpress:*:* 2.0.2 (excluding)