When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-05-17T16:48:53

Updated: 2024-08-03T19:28:23.704Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24323

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-05-17T17:15:08.393

Modified: 2021-05-24T18:15:19.300

Link: CVE-2021-24323

cve-icon Redhat

No data.