RSS   Vulnerabilities for 'Display post metadata'   RSS

2021-12-13
 
CVE-2021-24855

CWE-79
 

 
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

 


Copyright 2024, cxsecurity.com

 

Back to Top