ZeroHour

CVE-2021-24316

PoC ×2
CVSS 3.1
6.1 medium
EPSS
6%p93
Published
()
Modified
Description

The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter before output it back the page, leading to the Cross-SIte Scripting issue.

Vendors
wowthemes
Products
mediumish
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.