← back
CVE-2021-24331

Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSS

EPSS 0.7%CWE-79
The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, such as psb_distance, psb_buttonsize, psb_speed, only validating them client side. This could allow high privilege users (such as admin) to set XSS payloads in them

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →