Medium severity5.4NVD Advisory· Published Feb 25, 2021· Updated Jun 17, 2026
CVE-2021-3124
CVE-2021-3124
Description
Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to inject arbitrary code via the vars[0][name] field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:newtarget:custom_global_variables:1.0.5:*:*:*:*:wordpress:*:*
- robust.systems/Custom Global Variablesdescription
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/49406nvdExploitThird Party AdvisoryVDB Entry
- db.threatpress.com/vulnerability/custom-global-variables/wordpress-custom-global-variables-plugin-1-0-5-stored-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
News mentions
0No linked articles in our index yet.