Security Advisory

CVE-2021-24899

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-11-29 08:25:47
Last updated 2024-08-03 19:49:13
Assigner WPScan
State PUBLISHED

Description

The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.