CVE-2021-24593 Information

Description

The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its ‘Now closed message\ setting when outputting it in the backend and frontend leading to an Authenticated Stored Cross-Site Scripting issue

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: