← Back to CVE List

CVE-2021-25035

Published: 2022-01-24T08:15Z
Last Modified: 2024-11-21T05:54Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting > MITRE Terms of Use apply – see LICENSE‑MITRE.txt