CVE-2021-24245
06.05.2021, 13:15
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.
Vendor | Product | Version |
---|---|---|
trumani | stop_spammers | 𝑥 < 2021.9 |
𝑥
= Vulnerable software versions