The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d - Exploit, Third Party Advisory |
02 Sep 2021, 15:16
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:business_hours_indicator_project:business_hours_indicator:*:*:*:*:*:wordpress:*:* | |
References | (MISC) https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.4 |
30 Aug 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-30 15:15
Updated : 2024-11-21 05:53
NVD link : CVE-2021-24593
Mitre link : CVE-2021-24593
CVE.ORG link : CVE-2021-24593
JSON object : View
Products Affected
business_hours_indicator_project
- business_hours_indicator
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')