Vulnerability Details CVE-2021-25031
The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7.1 does not escape the effects parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-25031
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:-
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:1.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:2.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:3.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:3.0.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:4.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:5.4
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:5.5
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:5.7.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:5.8.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.4
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.5
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.6
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.7
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.7.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.8.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.8.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.9
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:6.9.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:7.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:7.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:7.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:7.4
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:7.5
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.4
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.5
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.6
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.7
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.8
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:8.9
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.3.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.3.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.3.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.3.4
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.4.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.4.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.4.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.5.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.5.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.5.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.5.3
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.6.0
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.6.1
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.6.2
-
cpe:2.3:a:oxilab:image_hover_effects_ultimate:9.7.0