Vulnerability Details CVE-2021-24389
The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.14
EPSS Ranking 93.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-24389
-
cpe:2.3:a:chimpgroup:foodbakery:1.1.0
-
cpe:2.3:a:chimpgroup:foodbakery:1.2.
-
cpe:2.3:a:chimpgroup:foodbakery:1.3
-
cpe:2.3:a:chimpgroup:foodbakery:1.4
-
cpe:2.3:a:chimpgroup:foodbakery:1.5
-
cpe:2.3:a:chimpgroup:foodbakery:1.6
-
cpe:2.3:a:chimpgroup:foodbakery:1.7
-
cpe:2.3:a:chimpgroup:foodbakery:1.8
-
cpe:2.3:a:chimpgroup:foodbakery:1.9
-
cpe:2.3:a:chimpgroup:foodbakery:2.0
-
cpe:2.3:a:chimpgroup:foodbakery:2.1