vulnerability

WordPress Plugin: language-bar-flags: CVE-2021-24431: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Aug 16, 2021
Added
May 15, 2025
Modified
Jun 24, 2025

Description

The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did not sanitise or escape them when generating the flag bar in the frontend. This could allow attackers to make a logged in admin change the settings, and set Cross-Site Scripting payload in them, which will be executed in the frontend for all users

Solution

language-bar-flags-plugin-cve-2021-24431
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.