Unrated severityNVD Advisory· Published Oct 25, 2021· Updated Aug 3, 2024
Request a Quote < 2.3.9 - Admin+ Stored Cross-Site Scripting
CVE-2021-24489
Description
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/36e8efe8-b29f-4c9e-9dd5-3e317aa43e0cmitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.