CVE-2021-24346
14.06.2021, 14:15
The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being contributor. The srch POST parameter is not validated, sanitised or escaped before using it in the echo statement, leading to a reflected XSS issue
Vendor | Product | Version |
---|---|---|
stock_in_\&_out_project | stock_in_\&_out | 𝑥 ≤ 1.0.4 |
𝑥
= Vulnerable software versions