Unrated severityNVD Advisory· Published Jul 12, 2021· Updated Aug 3, 2024
Request a Quote < 2.3.4 - Authenticated Stored XSS
CVE-2021-24420
Description
The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the 'All Quotes" table.
Affected products
1- Range: 2.3.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/426eafb1-0261-4e7e-8c70-75bf4c476f18mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.