CVE-2021-24785
25.10.2021, 14:15
The Great Quotes WordPress plugin through 1.0.0 does not sanitise and escape the Quote and Author fields of its Quotes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
Vendor | Product | Version |
---|---|---|
great-quotes_project | great-quotes | 𝑥 ≤ 1.0.0 |
𝑥
= Vulnerable software versions