ZeroHour

CVE-2021-24286

PoC ×2
CVSS 3.1
6.1 medium
EPSS
14%p96
Published
()
Modified
Description

The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue

Vendors
mooveagency
Products
redirect 404 to parent
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.