cleantalk
Vulnerabilities and Security Researches

Tournamatch, CVE-2024-5627

CVE, Research URL

CVE-2024-5627

Application

Tournamatch

Published on
Jul 13, 2024
Research Description
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.
Affected versions
Min -, max 4.6.1.
Status
vulnerable