mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-25 08:34:03 +02:00
835 B
835 B
CVE-2021-24540
Description
The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.
POC
Reference
- https://wpscan.com/vulnerability/67910e5d-ea93-418b-af81-c50d0e05d213
- https://wpscan.com/vulnerability/67910e5d-ea93-418b-af81-c50d0e05d213
Github
No PoCs found on GitHub currently.