The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/164327/WordPress-Select-All-Categories-And-Taxonomies-1.3.1-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
https://wpscan.com/vulnerability/56e1bb56-bfc5-40dd-b2d0-edef43d89bdf | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/164327/WordPress-Select-All-Categories-And-Taxonomies-1.3.1-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
https://wpscan.com/vulnerability/56e1bb56-bfc5-40dd-b2d0-edef43d89bdf | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/164327/WordPress-Select-All-Categories-And-Taxonomies-1.3.1-Cross-Site-Scripting.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://wpscan.com/vulnerability/56e1bb56-bfc5-40dd-b2d0-edef43d89bdf - Exploit, Third Party Advisory |
Information
Published : 2021-05-14 12:15
Updated : 2024-11-21 05:52
NVD link : CVE-2021-24287
Mitre link : CVE-2021-24287
CVE.ORG link : CVE-2021-24287
JSON object : View
Products Affected
mooveagency
- select_all_categories_and_taxonomies\,_change_checkbox_to_radio_buttons
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')