AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-24452

MEDIUM · CVSS 6.1 EPSS 2.00%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-07-19 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects WordPress, Java.

CVE
CVE-2021-24452
Severity
MEDIUM
CVSS
6.1
EPSS
2.00%
WordPress Java

Original NVD Description

The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper escaping. This could allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user's web browser, which could lead to full site compromise.

Related CVEs

Other vulnerabilities affecting the same vendor(s)