cleantalk
Vulnerabilities and Security Researches

My Tickets, CVE-2021-24796

CVE, Research URL

CVE-2021-24796

Application

My Tickets

Published on
Nov 17, 2021
Research Description
The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins
Affected versions
Min -, max 1.9.11.
Status
vulnerable