{"id":"CVE-2021-24841","details":"The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed","modified":"2026-07-09T06:35:04.971343Z","published":"2021-11-17T11:15:08.220Z","references":[{"type":"EVIDENCE","url":"https://mikadmin.fr/tech/XSS-Stored-Helpful-5b10bc7f40ab319f9797eb4abad4f420660.pdf"},{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/55d11acf-8c47-40da-be47-24f74fd7566e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pixelbart/helpful","events":[{"introduced":"0"},{"fixed":"ad7b2985282dd9948c8df00703d5f382d5df3216"}],"database_specific":{"cpe":"cpe:2.3:a:helpful_project:helpful:*:*:*:*:*:wordpress:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.4.59"}],"source":"CPE_RANGE"}}],"versions":["4.4.58","4.4.57","4.4.56","4.4.55","4.4.54","4.4.53","4.4.52","4.4.51","4.4.50","4.4.49","4.4.48","4.4.47","4.4.46","4.4.45","4.4.44","4.4.43","4.4.42","4.4.41","4.4.40","4.4.39","4.4.38","4.4.37","4.4.35","4.4.34","4.4.33","4.4.32","4.4.31","4.4.30","4.4.29","4.4.28","4.4.27","4.4.26","4.4.25","4.4.24","4.4.23","4.4.22","4.4.21","4.4.20","4.4.19","4.4.18","4.4.17","4.4.16","4.4.15","4.4.14","4.4.13","4.4.12","4.4.11","4.4.10","4.4.9","4.4.8","4.4.7","4.4.6","4.4.5","4.4.4","4.4.3","4.4.2","4.4.1","4.4.0","4.3.2","4.3.1","4.3.0","4.2.28","4.2.27","4.2.26","4.2.25","4.2.24","4.2.23","4.2.22","4.2.21","4.2.20","4.2.19","4.2.18","4.2.17","4.2.16","4.2.15","4.2.14","4.2.12","4.2.11","4.2.10","4.2.9","4.2.8","4.2.7","4.2.6","4.2.5","4.2.4","4.2.1","4.2.0","4.1.3","4.1.2","4.1.1","4.1.0","4.0.23","4.0.22","4.0.21","4.0.20"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24841.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}