mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 12:01:39 +02:00
918 B
918 B
CVE-2021-24524
Description
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.
POC
Reference
- https://wpscan.com/vulnerability/5a4774ec-c0ee-4c6b-92a6-fa10821ec336
- https://wpscan.com/vulnerability/5a4774ec-c0ee-4c6b-92a6-fa10821ec336