CVE Published: 21/12/2021 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo Gallery Status : PUBLISHED
CVE-2021-24738 Description
The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks