CVE-2021-24129
Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lead to Stored Cross-Site Scripting (XSS) vulnerabilities allowing low-privileged users (Contributor+) to inject arbitrary JavaScript code or HTML in posts where the Themify Custom Panel is embedded, which could lead to privilege escalation.
- Affected products
- Themify Portfolio Post
- Themify Portfolio Post
- < 1.1.6
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.7% (49th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-03-18
CVE-2021-24129 at NVD
1 known exploit for CVE-2021-24129
Proof-of-concept code and exploit modules indexed by Sploitus