Vulnerability CVE-2021-24724


Published: 2021-09-13

Description:
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/c1194a1e-bf33-4f3f-a4a6-27b76b1b1eeb
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29235
https://plugins.trac.wordpress.org/changeset/2573479/

Copyright 2024, cxsecurity.com

 

Back to Top