cve/2021/CVE-2021-24415.md
2024-05-25 21:48:12 +02:00

942 B
Raw Blame History

CVE-2021-24415

Description

The Polo Video Gallery Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

POC

Reference

Github

No PoCs found on GitHub currently.