CVE-2021-24710

The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:print-o-matic_project:print-o-matic:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2021-11-08 18:15

Updated : 2021-11-11 02:28


NVD link : CVE-2021-24710

Mitre link : CVE-2021-24710

CVE.ORG link : CVE-2021-24710


JSON object : View

Products Affected

print-o-matic_project

  • print-o-matic
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')