CVE-2021-24944
01.02.2022, 13:15
The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Vendor | Product | Version |
---|---|---|
cusmin | absolutely_glamorous_custom_admin | 𝑥 < 7.0 |
𝑥
= Vulnerable software versions