{ "id": "CVE-2024-6020", "sourceIdentifier": "contact@wpscan.com", "published": "2024-09-04T06:15:17.260", "lastModified": "2024-09-04T13:05:36.067", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting." }, { "lang": "es", "value": "El complemento Sign-up Sheets de WordPress anterior a la versi\u00f3n 2.2.13 no escapa a algunas URL generadas, as\u00ed como tampoco al par\u00e1metro $_SERVER['REQUEST_URI'] antes de mostrarlas nuevamente en atributos, lo que podr\u00eda generar un error de cross-site scripting reflejado." } ], "metrics": {}, "references": [ { "url": "https://wpscan.com/vulnerability/f3526320-3abd-4ddb-8f73-778741bd9c48/", "source": "contact@wpscan.com" } ] }