Headline
CVE-2021-36901: WordPress Age Gate plugin <= 2.17.0 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability - Patchstack
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker’s Age Gate plugin <= 2.17.0 at WordPress.
Fixed
6.1
CVSS 3.1 score Medium severity
Monitoring Coming soon
Vulnerable versions
<= 2.17.0
PSID
a28473c55146
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Publicly disclosed
2021-10-25
Details
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability was discovered by Nguyen Van Khanh (Patchstack Alliance) in the WordPress Age Gate plugin (versions <= 2.17.0).
Solution
Update the WordPress Age Gate plugin to the latest available version (at least 2.17.1).
References
CVE-2021-36901 Plugin changelog