RSS   Vulnerabilities for 'Ultimate nofollow'   RSS

2021-12-13
 
CVE-2021-24817

CWE-79
 

 
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks

 


Copyright 2024, cxsecurity.com

 

Back to Top