Security Advisory

CVE-2021-24418

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-07-12 19:20:53
Last updated 2024-08-03 19:28:23
Assigner WPScan
State PUBLISHED

Description

The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog