CVE-2021-24416
The StreamCast β Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
- Bplugins Streamcast Radio Player
- < 2.1.1
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.6% (46th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-10-18
CVE-2021-24416 at NVD
1 known exploit for CVE-2021-24416
Proof-of-concept code and exploit modules indexed by Sploitus