{"containers":{"cna":{"affected":[{"product":"Autoptimize","vendor":"Unknown","versions":[{"lessThan":"2.8.4","status":"affected","version":"2.8.4","versionType":"custom"}]}],"credits":[{"lang":"en","value":"m0ze"}],"descriptions":[{"lang":"en","value":"The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Cross-site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2021-05-24T10:58:05.000Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://wpscan.com/vulnerability/6678e064-ce21-4bb2-8c50-061073fb22fb"},{"tags":["x_refsource_MISC"],"url":"https://m0ze.ru/vulnerability/%5B2021-04-01%5D-%5BWordPress%5D-%5BCWE-79%5D-Autoptimize-WordPress-Plugin-v2.8.3.txt"}],"source":{"discovery":"UNKNOWN"},"title":"Autoptimize < 2.8.4 - Authenticated Stored Cross-Site Scripting (XSS)","x_generator":"WPScan CVE Generator","x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"contact@wpscan.com","ID":"CVE-2021-24332","STATE":"PUBLIC","TITLE":"Autoptimize < 2.8.4 - Authenticated Stored Cross-Site Scripting (XSS)"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Autoptimize","version":{"version_data":[{"version_affected":"<","version_name":"2.8.4","version_value":"2.8.4"}]}}]},"vendor_name":"Unknown"}]}},"credit":[{"lang":"eng","value":"m0ze"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues"}]},"generator":"WPScan CVE Generator","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross-site Scripting (XSS)"}]}]},"references":{"reference_data":[{"name":"https://wpscan.com/vulnerability/6678e064-ce21-4bb2-8c50-061073fb22fb","refsource":"CONFIRM","url":"https://wpscan.com/vulnerability/6678e064-ce21-4bb2-8c50-061073fb22fb"},{"name":"https://m0ze.ru/vulnerability/[2021-04-01]-[WordPress]-[CWE-79]-Autoptimize-WordPress-Plugin-v2.8.3.txt","refsource":"MISC","url":"https://m0ze.ru/vulnerability/[2021-04-01]-[WordPress]-[CWE-79]-Autoptimize-WordPress-Plugin-v2.8.3.txt"}]},"source":{"discovery":"UNKNOWN"}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T19:28:23.474Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://wpscan.com/vulnerability/6678e064-ce21-4bb2-8c50-061073fb22fb"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://m0ze.ru/vulnerability/%5B2021-04-01%5D-%5BWordPress%5D-%5BCWE-79%5D-Autoptimize-WordPress-Plugin-v2.8.3.txt"}]}]},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2021-24332","datePublished":"2021-05-24T10:58:05.000Z","dateReserved":"2021-01-14T00:00:00.000Z","dateUpdated":"2024-08-03T19:28:23.474Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}