← Back to CVE List

CVE-2021-39320

Published: 2021-09-01T15:15Z
Last Modified: 2024-11-21T06:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt