CVE detail
CVE-2021-24558 — CVE-2021-24558
Published 2021-08-23 · Modified 2026-06-17 · Vendor 3.7designs · Product project_status · Source nvd
MEDIUM
severity
CVSS-derived band
0.0067
EPSS probability
exploitation probability, 30d
49.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References