CVE-2021-24930

All FrameworksWordPressCWE-79CVE-2021-24930

CVE-2021-24930

State: PUBLISHED · Published: 2021-12-06 · Updated: 2024-08-03 · Assigner: WPScan
Description
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/24xxx/CVE-2021-24930.json