Sploitus

CVE-2021-24709

1 known exploit for CVE-2021-24709

The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues

Affected products
The Weather Effect
Awplife Weather Effect
< 1.3.6
Fix
Available
CVSS 3.1
4.8 MEDIUM
EPSS
0.6% (46th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-10-11
CVE-2021-24709 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24709

Proof-of-concept code and exploit modules indexed by Sploitus