CVE Database
/

CVE-2021-25014

Back to search

CVE-2021-25014

Published: Feb 14, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings which could lead to Stored Cross-Site Scripting issue.

VendorProductVersions

Unknown

Ibtana – WordPress Website Builder

affected
1.1.4.9 - < 1.1.4.9

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now