← back
CVE-2021-24211CWE-79

WordPress Related Posts <= 3.6.4 - Authenticated Stored Cross-Site Scripting (XSS)

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser.