The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-08-30 08:15
Updated : 2021-09-02 08:16
NVD link : CVE-2021-24593
Mitre link : CVE-2021-24593
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
business_hours_indicator_project
- business_hours_indicator