Security Advisory

CVE-2021-24987

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-04-11 14:40:37
Last updated 2024-08-03 19:49:14
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue.