CVE-2021-24420 – Request a Quote < 2.3.4 - Authenticated Stored XSS
https://notcve.org/view.php?id=CVE-2021-24420
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table. El plugin Request a Quote de WordPress versiones anteriores a 2.3.4, no saneaba y escapaba de algunos de sus campos quote cuando se añadía/editaba un quote como administrador, conllevando a problemas de tipo Cross-Site Scripting Almacenado cuando el quote se mostraba en la tabla "All Quotes" • https://wpscan.com/vulnerability/426eafb1-0261-4e7e-8c70-75bf4c476f18 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-24489 – Request a Quote < 2.3.9 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24489
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. El plugin Request a Quote de WordPress versiones anteriores a 2.3.5, no sanea, comprueba o escapa de algunas de sus configuraciones en el panel de administración, conllevando a problemas de tipo Cross-Site Scripting Almacenado y autenticado, incluso cuando la capacidad unfiltered_html no está permitida The Request a Quote WordPress plugin before 2.3.5 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. • https://wpscan.com/vulnerability/36e8efe8-b29f-4c9e-9dd5-3e317aa43e0c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •