Filtered by vendor Bootstrapped Subscriptions
Filtered by product Dynamic Widgets Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-24933 1 Bootstrapped 1 Dynamic Widgets 2024-11-21 5.4 Medium
The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue