Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-24933
HistoryFeb 28, 2022 - 9:15 a.m.

Cross site scripting

2022-02-2809:15:00
PRIOn knowledge base
www.prio-n.com

0.001 Low

EPSS

Percentile

24.8%

The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an attribute when using the term_tree AJAX action (available to any authenticated users), leading to a Reflected Cross-Site Scripting issue

CPENameOperatorVersion
dynamic_widgetsle1.5.16

0.001 Low

EPSS

Percentile

24.8%