CVE-2021-24922
CRITICAL9.0CVSS v3
6.0CVSS v2
0.11%
EPSS (exploit probability)
CWE-352CWE
Description
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected routers (0)
No routers currently mapped to this CVE in our database.