Unrated severityNVD Advisory· Published May 17, 2021· Updated Aug 3, 2024
All 404 Redirect to Homepage < 1.21 - Authenticated Reflected Cross-Site Scripting (XSS)
CVE-2021-24326
Description
The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.
Affected products
1- Range: <1.21
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/63d6ca03-e0df-40db-9839-531c13619094mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.