1 results (0.003 seconds)
CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1
CVE-2021-24445 – My Site Audit <= 1.2.4 - Authenticated Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24445
19 Jul 2021 — The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue El plugin de WordPress My Site Audit versiones hasta 1.2.4, no sanea o escapa del campo Audit Name cuando se crea una auditoría, permitiendo a usuarios con altos privilegios ajustar cargas útiles de JavaScri... • https://wpscan.com/vulnerability/d60634a3-ca39-43be-893b-ff9ba625360f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •