CVE-2021-24245

CVE-2021-24245

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

Source: CVE-2021-24245

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다