CVE-2021-24440

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
12/07/2021
Last modified:
15/07/2021

Description

The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fetchdesigns:sign-up_sheets:*:*:*:*:*:wordpress:*:* 1.0.14 (excluding)