CVE-2021-24124

Publication date

2021-03-18 14:57:48

Family

WPScan

State

PUBLISHED

Description

Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.