Cross-Site Scripting (XSS) Vulnerability in MotoPress WordPress Plugin

Cross-Site Scripting (XSS) Vulnerability in MotoPress WordPress Plugin

CVE-2021-24724 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s

Learn more about our Wordpress Pen Testing.