CVE-2021-24233
The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute.
- Affected products
- Cooked Pro
- Boxystudio Cooked
- < 1.7.5.6
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.7% (77th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-04-22
CVE-2021-24233 at NVD
2 known exploits for CVE-2021-24233
Proof-of-concept code and exploit modules indexed by Sploitus