CVE-2021-24617
The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues
- Gamepress Project Gamepress
- ≤ 1.1.0
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-10-18
CVE-2021-24617 at NVD
1 known exploit for CVE-2021-24617
Proof-of-concept code and exploit modules indexed by Sploitus