The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-08-30 15:15
Updated : 2021-09-02 15:16
NVD link : CVE-2021-24593
Mitre link : CVE-2021-24593
CVE.ORG link : CVE-2021-24593
JSON object : View
Products Affected
business_hours_indicator_project
- business_hours_indicator
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')