CVE-2021-24444
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.
Productos afectados
Unknown · TaxoPress – Create and Manage Taxonomies, Tags, CategoriesPoCs públicas encontradas — 2
cve_referencepacketstormsecurity.com/files/164604/WordPress-TaxoPress-3.0.7.1-Cross-Site-Scripting.htmlno verificadoexploitdbwww.exploit-db.com/exploits/50442no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →