← Back to CVE List
CVE-2021-24322
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt