Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-25060
HistoryFeb 21, 2022 - 11:15 a.m.

Cross site scripting

2022-02-2111:15:00
PRIOn knowledge base
www.prio-n.com
1

0.001 Low

EPSS

Percentile

24.8%

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

0.001 Low

EPSS

Percentile

24.8%

Related for PRION:CVE-2021-25060