CVE-2021-24290
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.
Affected (1)
Products: De Baat: Store Locator Plus
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.5.15 |
References (4)
Source: contact@wpscan.com
Third Party Advisory
Source: contact@wpscan.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.