CVE-2021-24593
The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
- Affected products
- Business Hours Indicator
- Business Hours Indicator Project Business Hours Indicator
- < 2.3.5
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.6% (47th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-08-30
CVE-2021-24593 at NVD
1 known exploit for CVE-2021-24593
Proof-of-concept code and exploit modules indexed by Sploitus