ZeroHour

CVE-2021-24468

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p48
Published
()
Modified
Description

The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues

Vendors
bozdoz
Products
leaflet map
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.