mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-12 13:31:34 +02:00
848 B
848 B
CVE-2021-24699
Description
The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
POC
Reference
- https://wpscan.com/vulnerability/4f5c3f75-0501-4a1a-95ea-cbfd3fc96852
- https://wpscan.com/vulnerability/4f5c3f75-0501-4a1a-95ea-cbfd3fc96852
Github
No PoCs found on GitHub currently.