WordPress W3 Total Cache plugin before 2.1.5 is susceptible to cross-site scripting via the extension parameter in the Extensions dashboard, when the setting ‘Anonymously track usage to improve product quality’ is enabled. The parameter is output in a JavaScript context without proper escaping. This can allow an attacker, who can convince an authenticated admin into clicking a link, to run malicious JavaScript within the user’s web browser, which could lead to full site compromise.
View the template here CVE-2021-24452.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2021-24452