Beveiligingsadvies

CVE-2021-24745

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-11-29 08:25:29
Laatst bijgewerkt 2024-08-03 19:42:16
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.