Unrated severityNVD Advisory· Published Dec 13, 2021· Updated Aug 3, 2024
Ultimate NoFollow <= 1.4.8 - Contributor+ Stored Cross-Site Scripting
CVE-2021-24817
Description
The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
Affected products
1- Range: 1.4.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/ccb27d2e-2d2a-40d3-ba7e-bcd5e5012a9amitrex_refsource_MISC
News mentions
0No linked articles in our index yet.