← back
CVE-2021-24476

Steam Group Viewer <= 2.1 - Authenticated Stored Cross-Site Scripting (XSS)

EPSS 0.6%CWE-79
The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings before outputting it in the page, leading to an authenticated Stored Cross-Site Scripting issue

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →