CVE-2021-24124
Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.
- Affected products
- Wp Shieldon
- Terryl Wp Shieldon
- ≤ 1.6.3
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.1% (65th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-03-18
CVE-2021-24124 at NVD
1 known exploit for CVE-2021-24124
Proof-of-concept code and exploit modules indexed by Sploitus