cleantalk
Vulnerabilities and Security Researches

WP Mapa Politico España, CVE-2021-24609

CVE, Research URL

CVE-2021-24609

Published on
Sep 20, 2021
Research Description
The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Affected versions
Min -, max 3.7.0.
Status
vulnerable