Unrated severityNVD Advisory· Published Jul 12, 2021· Updated Aug 3, 2024
Admin Columns Free (< 4.3.2) & Pro (< 5.5.2) - Authenticated Stored Cross-Site Scripting (XSS) in Custom Field
CVE-2021-24365
Description
The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for tables. Each column had a type. The type "Custom Field" allowed to choose an arbitrary database column to display in the table. There was no escaping applied to the contents of "Custom Field" columns.
Affected products
1- Range: 4.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- wpscan.com/vulnerability/fdbeb137-b404-46c7-85fb-394a3bdac388mitrex_refsource_CONFIRM
- www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2021-032.txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.