← Back to CVE List

CVE-2021-24296

Published: 2021-05-24T11:15Z
Last Modified: 2024-11-21T05:52Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege users such as administrators to set XSS payloads in them which will then be triggered in pages where reviews are enabled > MITRE Terms of Use apply – see LICENSE‑MITRE.txt