CVE-2021-24680 Details
Description
The WP Travel Engine WordPress plugin before 5.3.1 does not escape the Description field in the Trip Destination/Activities/Trip Type and Pricing Category pages, allowing users with a role as low as editor to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed
A stored cross-site scripting vulnerability has been identified in the WP Travel Engine WordPress plugin, affecting versions prior to 5.3.1. The issue arises because the plugin does not properly escape the Description field in Trip Destination, Activities, Trip Type, and Pricing Category pages. This flaw allows users with editor roles to inject malicious scripts, even when the unfiltered_html capability is restricted.
Users are advised to update the WP Travel Engine plugin to version 5.3.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/30f2a0d5-7959-436c-9860-2535020e82d3 | CVE | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/30f2a0d5-7959-436c-9860-2535020e82d3 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wptravelengine wp travel engine | < 5.3.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 7, 2022 | Initial Analysis | [email protected] |