CVE-2021-24578
EUVD-2021-1149021.12.2021, 09:15
The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| themeboy | sportspress | 𝑥 < 2.7.9 |
𝑥
= Vulnerable software versions