The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:35:20.208Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-20T10:15:08.783

Modified: 2024-11-21T05:53:22.817

Link: CVE-2021-24597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.