Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-24782
HistoryDec 13, 2021 - 11:15 a.m.

Cross site scripting

2021-12-1311:15:00
PRIOn knowledge base
www.prio-n.com
2

0.001 Low

EPSS

Percentile

24.8%

The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CPENameOperatorVersion
flex_local_fontsle1.0.0

0.001 Low

EPSS

Percentile

24.8%