cleantalk
Vulnerabilities and Security Researches

School Management System – WPSchoolPress, CVE-2021-24664

CVE, Research URL

CVE-2021-24664

Published on
Nov 08, 2021
Research Description
The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_field() but does not escape them before outputting in attributes, resulting in Stored Cross-Site Scripting issues.
Affected versions
Min -, max 2.2.5.
Status
vulnerable