ZeroHour

CVE-2021-24587

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p48
Published
()
Modified
Description

The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.

Vendors
zeesweb
Products
splash header
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.