CVE-2021-24246
06.05.2021, 13:15
The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues
Vendor | Product | Version |
---|---|---|
purethemes | workscout | 𝑥 < 2.0.33 |
purethemes | workscout_core | 𝑥 < 1.3.4 |
𝑥
= Vulnerable software versions
References