mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-11 00:14:52 +02:00
893 B
893 B
CVE-2021-24876
Description
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
POC
Reference
- https://wpscan.com/vulnerability/e77c2493-993d-418d-9629-a1f07b5a2b6f
- https://wpscan.com/vulnerability/e77c2493-993d-418d-9629-a1f07b5a2b6f
Github
No PoCs found on GitHub currently.