Security Advisory

CVE-2021-24878

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-02-07 15:47:10
Last updated 2024-08-03 19:49:12
Assigner WPScan
State PUBLISHED

Description

The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue