mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-30 09:09:31 +02:00
987 B
987 B
CVE-2021-24412
Description
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
POC
Reference
- https://wpscan.com/vulnerability/c4ed3e52-cbe0-46dc-ab43-65de78cfb225
- https://wpscan.com/vulnerability/c4ed3e52-cbe0-46dc-ab43-65de78cfb225
Github
No PoCs found on GitHub currently.