Vulnerability Details CVE-2021-24424
The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.5%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-24424
-
cpe:2.3:a:webfactoryltd:wp_reset:-
-
cpe:2.3:a:webfactoryltd:wp_reset:1.0
-
cpe:2.3:a:webfactoryltd:wp_reset:1.1
-
cpe:2.3:a:webfactoryltd:wp_reset:1.11
-
cpe:2.3:a:webfactoryltd:wp_reset:1.20
-
cpe:2.3:a:webfactoryltd:wp_reset:1.25
-
cpe:2.3:a:webfactoryltd:wp_reset:1.30
-
cpe:2.3:a:webfactoryltd:wp_reset:1.35
-
cpe:2.3:a:webfactoryltd:wp_reset:1.40
-
cpe:2.3:a:webfactoryltd:wp_reset:1.45
-
cpe:2.3:a:webfactoryltd:wp_reset:1.50
-
cpe:2.3:a:webfactoryltd:wp_reset:1.55
-
cpe:2.3:a:webfactoryltd:wp_reset:1.60
-
cpe:2.3:a:webfactoryltd:wp_reset:1.65
-
cpe:2.3:a:webfactoryltd:wp_reset:1.70
-
cpe:2.3:a:webfactoryltd:wp_reset:1.75
-
cpe:2.3:a:webfactoryltd:wp_reset:1.77
-
cpe:2.3:a:webfactoryltd:wp_reset:1.80
-
cpe:2.3:a:webfactoryltd:wp_reset:1.81
-
cpe:2.3:a:webfactoryltd:wp_reset:1.82
-
cpe:2.3:a:webfactoryltd:wp_reset:1.83
-
cpe:2.3:a:webfactoryltd:wp_reset:1.84
-
cpe:2.3:a:webfactoryltd:wp_reset:1.85
-
cpe:2.3:a:webfactoryltd:wp_reset:1.86