mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-14 15:08:03 +02:00
894 B
894 B
CVE-2021-24599
Description
The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authentication and will render a user supplied value in the HTML response without escaping or sanitizing the data.
POC
Reference
- https://wpscan.com/vulnerability/625a272f-5c69-4f6a-8eee-32f70cd4a558
- https://wpscan.com/vulnerability/625a272f-5c69-4f6a-8eee-32f70cd4a558
Github
No PoCs found on GitHub currently.