← back
CVE-2021-24127CWE-79

ThirstyAffiliates < 3.9.3 - Authenticated Stored XSS

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.7%
exploitation probability
0.7%top 52% of all CVEs
observed exploitation
nono source reports it
Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions before 3.9.3, was vulnerable to authenticated Stored Cross-Site Scripting (XSS), which could lead to privilege escalation.