The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used

Subscriptions

Vendors Products
You-shang Project Subscribe
You-shang Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-11509 The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-03T19:35:20.208Z

Reserved: 2021-01-14T00:00:00.000Z

Link: CVE-2021-24597

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-20T10:15:08.783

Modified: 2024-11-21T05:53:22.817

Link: CVE-2021-24597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses