Sploitus

CVE-2021-24574

1 known exploit for CVE-2021-24574

The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.

Affected products
Simple Banner
Simple Banner Project Simple Banner
< 2.10.4
Fix
Available
CVSS 3.1
4.8 MEDIUM
EPSS
0.7% (50th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-08-23
CVE-2021-24574 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24574

Proof-of-concept code and exploit modules indexed by Sploitus