Medium severity4.8NVD Advisory· Published Oct 25, 2021· Updated Jun 17, 2026
CVE-2021-24489
CVE-2021-24489
Description
The Request a Quote WordPress plugin before 2.3.9 does not sanitise, validate or escape some of its settings in the admin dashboard, leading to authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:emarketdesign:request_a_quote:*:*:*:*:*:wordpress:*:*Range: <2.3.5
0+ 1 more
- (no CPE)range: 0
- (no CPE)range: <2.3.9
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/36e8efe8-b29f-4c9e-9dd5-3e317aa43e0cnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.