ZeroHour

CVE-2021-24658

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p50
Published
()
Modified
Description

The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)

Vendors
erident custom login and dashboard project
Products
erident custom login and dashboard
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.