Medium severity4.8NVD Advisory· Published Nov 29, 2021· Updated Jun 17, 2026
CVE-2021-24899
CVE-2021-24899
Description
The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:media-tags_project:media-tags:*:*:*:*:*:*:*:*Range: <=3.2.0.2
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=3.2.0.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/cf4b266c-d68e-4add-892a-d01a31987a4bnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.