CVE-2021-47910

AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page is viewed, affecting all users who access the plugin interface.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-10 13:16

Updated : 2026-07-25 11:10


NVD link : CVE-2021-47910

Mitre link : CVE-2021-47910

CVE.ORG link : CVE-2021-47910


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')