The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/2365a9d0-f6f4-4602-9804-5af23d0cb11d | Exploit Third Party Advisory |
https://m0ze.ru/vulnerability/[2021-02-10]-[WordPress]-[CWE-79]-WorkScout-WordPress-Theme-v2.0.33.txt | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-05-06 06:15
Updated : 2021-05-13 09:19
NVD link : CVE-2021-24246
Mitre link : CVE-2021-24246
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
purethemes
- workscout
- workscout_core