The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-03-07T08:16:15

Updated: 2022-03-07T08:16:15

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-25038

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-07T09:15:08.590

Modified: 2022-03-11T20:04:45.470


Link: CVE-2021-25038

JSON object: View

cve-icon Redhat Information

No data.

CWE