ZeroHour

CVE-2021-34654

PoC ×2
CVSS 3.1
6.1 medium
EPSS
<1%p58
Published
()
Modified
Description

The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] parameter found in the ~/pages/admin-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.

Vendors
custom post type relations project
Products
custom post type relations
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.