ZeroHour

CVE-2021-24683

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p35
Published
()
Modified
Description

The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.

Vendors
awplife
Products
weather effect
Ecosystems
WordPress
Weakness
CWE-79, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.