The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortcode is used, leading to Reflected Cross-Site Scripting issues
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/c4e50dd2-450f-413d-b15f-ece413e42157 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-02-28 09:15
Updated : 2022-03-08 16:50
NVD link : CVE-2021-25034
Mitre link : CVE-2021-25034
CVE.ORG link : CVE-2021-25034
JSON object : View
Products Affected
wp_user_project
- wp_user
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')