CVE-2021-24609
20.09.2021, 10:15
The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Vendor | Product | Version |
---|---|---|
wp_mapa_politico_espana_project | wp_mapa_politico_espana | 𝑥 < 3.7.0 |
𝑥
= Vulnerable software versions