Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-24134
HistoryMar 18, 2021 - 3:15 p.m.

Cross site scripting

2021-03-1815:15:00
PRIOn knowledge base
www.prio-n.com
1

0.001 Low

EPSS

Percentile

24.8%

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

CPENameOperatorVersion
constant_contact_formslt1.8.8

0.001 Low

EPSS

Percentile

24.8%

Related for PRION:CVE-2021-24134