vulnerability

WordPress Plugin: language-bar-flags: CVE-2021-24431: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Aug 16, 2021
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

Solution

language-bar-flags-plugin-cve-2021-24431
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.