ZeroHour

CVE-2021-24332

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p48
Published
()
Modified
Description

The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allowing high privilege users to set XSS payloads in them, leading to stored Cross-Site Scripting issues

Vendors
autoptimize
Products
autoptimize
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.