Sploitus

CVE-2021-24561

1 known exploit for CVE-2021-24561

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

Affected products
Wp Sms
Veronalabs Wp Sms
< 5.4.13
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.7% (49th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2021-08-23
CVE-2021-24561 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24561

Proof-of-concept code and exploit modules indexed by Sploitus