The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as subscriber), or unauthenticated user via a CSRF vector to update them and perform such attack.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2021-09-20T10:06:37

Updated: 2021-09-20T10:06:37

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-24618

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-09-20T10:15:09.137

Modified: 2022-12-20T22:07:44.353


Link: CVE-2021-24618

JSON object: View

cve-icon Redhat Information

No data.