Medium severity5.4NVD Advisory· Published Nov 1, 2021· Updated Jun 17, 2026
CVE-2021-24723
CVE-2021-24723
Description
The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wpreactions:wp_reactions_lite:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:wpreactions:wp_reactions_lite:*:*:*:*:*:wordpress:*:*range: <1.3.6
- (no CPE)range: 1.3.6
- Range: <1.3.6
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/0a46ae96-41e5-4b52-91c3-409f7387aeccnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.