CVE-2021-24535
Status: ModifiedMedium (6.1)—
The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting payload in the Message Content. Depending on the options set, the XSS payload can be triggered either in the backend only (in the plugin's settings), or both frontend and backend.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Base score: 6.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.41%
- Percentile among all scored CVEs: 33
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79, CWE-352
References
Raw JSON (NVD)
Show
{
"id": "CVE-2021-24535",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "Light Messages",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom",
"lessThanOrEqual": "1.0"
}
]
}
]
}
],
"published": "2021-08-16T11:15:08.953",
"references": [
{
"url": "https://wpscan.com/vulnerability/351de889-9c0a-4637-bd06-0e1fe1d7e89f",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/351de889-9c0a-4637-bd06-0e1fe1d7e89f",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
},
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting payload in the Message Content. Depending on the options set, the XSS payload can be triggered either in the backend only (in the plugin's settings), or both frontend and backend."
},
{
"lang": "es",
"value": "El plugin de WordPress Light Messages versiones hasta 1.0, carece de una comprobación CSRF cuando actualiza su configuración, y no sanea el contenido de sus mensajes en ellos (incluso con el unfiltered_html deshabilitado). Como resultado, un atacante podría hacer a un administrador conectado actualizar la configuración con valores arbitrarios, y ajustar una carga útil de tipo Cross-Site Scripting en el contenido del mensaje. Dependiendo de las opciones configuradas, la carga útil de tipo XSS puede desencadenarse sólo en el backend (en la configuración del plugin), o tanto en el frontend como en el backend."
}
],
"lastModified": "2026-06-17T03:40:11.830",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:light_messages_project:light_messages:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "5C91B0CB-E18A-4E80-9452-2DD1288159DD",
"versionEndIncluding": "1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}