CVE-2021-24309
The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize input, allowing a user to inject javascript code using the <script> HTML tags and cause a stored XSS issue
- Affected products
- Weekly Schedule
- Weekly Schedule Project Weekly Schedule
- < 3.4.3
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.7% (49th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-06-01
CVE-2021-24309 at NVD
1 known exploit for CVE-2021-24309
Proof-of-concept code and exploit modules indexed by Sploitus