Логотип exploitDog
bind:CVE-2021-24433
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24433

Количество 2

Количество 2

nvd логотип

CVE-2021-24433

около 2 лет назад

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-f6fq-4q55-rg2f

около 2 лет назад

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24433

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-f6fq-4q55-rg2f

The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "category_sims", "order_sims", "orderby_sims", "period_sims", and "tag_sims" use allowed URL protocols, which can lead to stored cross-site scripting by users with a role as low as Contributor

CVSS3: 5.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу