The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settings tab before outputting them back in the page, leading to authenticated stored Cross-Site Scripting issues
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2021-05-14T11:38:16

Updated: 2021-05-14T11:38:16

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-24277

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2021-05-14T12:15:08.160

Modified: 2023-11-07T03:31:09.340


Link: CVE-2021-24277

JSON object: View

cve-icon Redhat Information

No data.

CWE