Medium severity5.4NVD Advisory· Published Jun 1, 2021· Updated Jun 17, 2026
CVE-2021-24322
CVE-2021-24322
Description
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:deliciousbrains:database_backup:*:*:*:*:*:wordpress:*:*Range: <2.4
- Range: <2.4
- Range: 2.4
Patches
Vulnerability mechanics
References
2- m0ze.ru/vulnerability/%5B2021-04-04%5D-%5BWordPress%5D-%5BCWE-79%5D-WP-DB-Backup-WordPress-Plugin-v2.3.3.txtnvdExploitThird Party Advisory
- wpscan.com/vulnerability/6bea6301-0762-45c3-a4eb-15d6ac4f9f37nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.