cve/2021/CVE-2021-24196.md
2024-06-18 02:51:15 +02:00

867 B
Raw Blame History

CVE-2021-24196

Description

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the token_error parameter can be controlled by users and it is directly echoed without being sanitized

POC

Reference

Github

No PoCs found on GitHub currently.