Description
Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Deactivate and delete.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23487 | Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), could be exploited by users with Editor or higher role. |
References
History
Fri, 28 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:07:37.578Z
Reserved: 2021-07-19T00:00:00.000Z
Link: CVE-2021-36911
Updated: 2024-08-04T01:01:59.932Z
Status : Modified
Published: 2021-12-10T17:15:07.537
Modified: 2024-11-21T06:14:17.263
Link: CVE-2021-36911
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD