CVE-2021-25086

The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:advanced_page_visit_counter_project:advanced_page_visit_counter:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2022-05-02 16:15

Updated : 2024-02-28 19:09


NVD link : CVE-2021-25086

Mitre link : CVE-2021-25086

CVE.ORG link : CVE-2021-25086


JSON object : View

Products Affected

advanced_page_visit_counter_project

  • advanced_page_visit_counter
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')