Vulnerabilities (CVE)

Filtered by vendor Ultimate Nofollow Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24817 1 Ultimate Nofollow Project 1 Ultimate Nofollow 2024-02-28 3.5 LOW 5.4 MEDIUM
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks