Логотип exploitDog
bind:CVE-2021-24918
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24918

Количество 2

Количество 2

nvd логотип

CVE-2021-24918

около 4 лет назад

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-j9qp-w82r-g5cf

около 4 лет назад

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24918

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-j9qp-w82r-g5cf

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу