Логотип exploitDog
bind:CVE-2021-24789
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24789

Количество 2

Количество 2

nvd логотип

CVE-2021-24789

больше 4 лет назад

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-grw5-p86m-w8x6

больше 3 лет назад

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24789

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-grw5-p86m-w8x6

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу