Lucene search

K
cvelistWPScanCVELIST:CVE-2021-25014
HistoryFeb 14, 2022 - 9:20 a.m.

CVE-2021-25014 Ibtana < 1.1.4.9 - Subscriber+ Settings Update to Stored XSS

2022-02-1409:20:42
CWE-862
WPScan
www.cve.org

4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.8%

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin’s settings which could lead to Stored Cross-Site Scripting issue.

CNA Affected

[
  {
    "product": "Ibtana – WordPress Website Builder",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.1.4.9",
        "status": "affected",
        "version": "1.1.4.9",
        "versionType": "custom"
      }
    ]
  }
]

4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

24.8%

Related for CVELIST:CVE-2021-25014