cve/2021/CVE-2021-24196.md
2025-09-29 21:09:30 +02:00

870 B
Raw Blame History

CVE-2021-24196

Description

The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the token_error parameter can be controlled by users and it is directly echoed without being sanitized

POC

Reference

Github