Description
The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11749 | The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:42:17.209Z
Reserved: 2021-01-14T15:03:46.804Z
Link: CVE-2021-24837
No data.
Status : Modified
Published: 2023-01-23T15:15:13.063
Modified: 2024-11-21T05:53:51.683
Link: CVE-2021-24837
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD