ZeroHour

CVE-2021-38316

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p59
Published
()
Modified
Description

The WP Academic People List WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category_name parameter in the ~/admin-panel.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.4.1.

Vendors
wp academic people list project
Products
wp academic people list
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.