Vulnerability Description
The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending on the payload used
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| You-Shang Project | You-Shang | <= 1.0.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/37554d0e-68e2-4df9-8c59-65f5cd7f184eExploitThird Party Advisory
- https://wpscan.com/vulnerability/37554d0e-68e2-4df9-8c59-65f5cd7f184eExploitThird Party Advisory
FAQ
What is CVE-2021-24597?
CVE-2021-24597 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-Site Scripting issues in frontend posts and the plugins settings page depending o...
How severe is CVE-2021-24597?
CVE-2021-24597 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24597?
Check the references section above for vendor advisories and patch information. Affected products include: You-Shang Project You-Shang.