1 results (0.006 seconds)
CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1
CVE-2021-24211 – WordPress Related Posts <= 3.6.4 - Authenticated Stored Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2021-24211
19 Mar 2021 — The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser. El plugin de WordPress Related Posts versiones hasta 3.6.4, contiene una vulnerabilidad de tipo XSS almacenado autenticada (admin+) en el campo title en la página de configuración. Al explotar que un atacante pueda ser capaz de ejecutar código JavaScript en el na... • https://wpscan.com/vulnerability/37e0a033-3dee-476d-ae86-68354e8f0b1c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •