CVE-2021-24732
EUVD-2021-1164418.10.2021, 14:15
The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dearhive | dearflip | 𝑥 < 1.7.10 |
𝑥
= Vulnerable software versions