Unrated severityNVD Advisory· Published Jun 1, 2021· Updated Aug 3, 2024
Database Backup for WordPress < 2.4 - Authenticated Persistent Cross-Site Scripting (XSS)
CVE-2021-24322
Description
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
Affected products
1- Range: 2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- m0ze.ru/vulnerability/%5B2021-04-04%5D-%5BWordPress%5D-%5BCWE-79%5D-WP-DB-Backup-WordPress-Plugin-v2.3.3.txtmitrex_refsource_MISC
- wpscan.com/vulnerability/6bea6301-0762-45c3-a4eb-15d6ac4f9f37mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.