Lucene search

K
cvelistWPScanCVELIST:CVE-2021-24623
HistorySep 13, 2021 - 5:56 p.m.

CVE-2021-24623 WordPress Advanced Ticket System < 1.0.64 - Authenticated Stored Cross-Site Scripting (XSS)

2021-09-1317:56:36
CWE-79
WPScan
www.cve.org
2
wordpress
ticket system
cross-site scripting

EPSS

0.001

Percentile

24.8%

The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CNA Affected

[
  {
    "product": "WordPress Advanced Ticket System, Elite Support Helpdesk",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.0.64",
        "status": "affected",
        "version": "1.0.64",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

24.8%

Related for CVELIST:CVE-2021-24623