CVE-2021-24578
21.12.2021, 09:15
The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue
Vendor | Product | Version |
---|---|---|
themeboy | sportspress | 𝑥 < 2.7.9 |
𝑥
= Vulnerable software versions