cve/2021/CVE-2021-24524.md
2024-05-25 21:48:12 +02:00

845 B
Raw Blame History

CVE-2021-24524

Description

The GiveWP Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level setting of its Donation Forms, allowing high privilege users to use Cross-Site Scripting payloads in them.

POC

Reference

Github