CVE-2021-24796

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/11/2021
Last modified:
19/11/2021

Description

The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:my_tickets_project:my_tickets:*:*:*:*:*:wordpress:*:* 1.8.31 (excluding)