mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-30 13:19:29 +02:00
845 B
845 B
CVE-2021-24996
Description
The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter before outputting it back in the page leading to a Reflected Cross-Site Scripting
POC
Reference
- https://wpscan.com/vulnerability/6ee14423-f7ff-4433-987a-a1a6b7bd65e3
- https://wpscan.com/vulnerability/6ee14423-f7ff-4433-987a-a1a6b7bd65e3
Github
No PoCs found on GitHub currently.