CVE-2021-25038

All FrameworksWordPressCWE-79CVE-2021-25038

CVE-2021-25038

State: PUBLISHED · Published: 2022-03-07 · Updated: 2024-08-03 · Assigner: WPScan
Description
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/25xxx/CVE-2021-25038.json