← Back to CVE List

CVE-2021-24642

Published: 2021-10-18T14:15Z
Last Modified: 2024-11-21T05:53Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform any sanitisation, escaping or validation on them. This could allow attackers to make logged in admin change them and could lead to RCE (via a file upload) as well as XSS > MITRE Terms of Use apply – see LICENSE‑MITRE.txt