The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-12-13T10:41:19

Updated: 2024-08-03T19:49:13.810Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24922

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-12-13T11:15:09.470

Modified: 2021-12-15T19:17:30.217

Link: CVE-2021-24922

cve-icon Redhat

No data.