CVE-2021-24418
Smooth Scroll Page Up/Down Buttons <= 1.4 - Authenticated Stored XSS via psb_positioning
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Jul 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog
Affected products
Mark Senff · Smooth Scroll Page Up/Down ButtonsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →