CVE Published: 12/07/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Mark Senff |
Product: Smooth Scroll Page Up/Down Buttons Status : PUBLISHED
CVE-2021-24418 Description
The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_positioning settings, allowing high privilege users such as admin to set an XSS payload in it, which will be executed in all pages of the blog