ZeroHour

CVE-2021-24536

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p35
Published
()
Modified
Description

The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issue

Vendors
custom login redirect project
Products
custom login redirect
Ecosystems
WordPress
Weakness
CWE-79, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.