The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-05-24T10:58:04

Updated: 2024-08-03T19:28:23.433Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-05-24T11:15:08.070

Modified: 2021-05-28T18:17:18.577

Link: CVE-2021-24296

cve-icon Redhat

No data.