mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
18 lines
875 B
Markdown
18 lines
875 B
Markdown
### [CVE-2021-24180](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24180)
|
|

|
|

|
|
&color=brighgreen)
|
|
|
|
### Description
|
|
|
|
Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Reflected Cross-Site Scripting (XSS) vulnerability within the 'lang' GET parameter while editing a post, triggered when users with the capability of editing posts access a malicious URL.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://wpscan.com/vulnerability/7593d5c8-cbc2-4469-b36b-5d4fb6d49718
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|