ZeroHour

CVE-2021-24593

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p48
Published
()
Modified
Description

The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue

Vendors
business hours indicator project
Products
business hours indicator
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.