← Back to CVE List

CVE-2024-6020

Published: 2024-09-04T06:15Z
Last Modified: 2024-10-07T15:42Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt