CVE-2021-24322
01.06.2021, 14:15
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
Vendor | Product | Version |
---|---|---|
deliciousbrains | database_backup | 𝑥 < 2.4 |
𝑥
= Vulnerable software versions
References