Sploitus

CVE-2021-24634

1 known exploit for CVE-2021-24634

The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properties of the Recipe Card Block (such as ingredientsLayout, iconSet, steps, ingredients, recipeTitle, or settings), which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.

Affected products
The Recipe Card Blocks
Wpzoom Recipe Card Blocks For Gutenberg \& Elementor
< 2.8.3
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.6% (47th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-09-27
CVE-2021-24634 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24634

Proof-of-concept code and exploit modules indexed by Sploitus