Security Advisory

CVE-2021-24994

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-02-28 09:06:27
Last updated 2024-08-03 19:49:14
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue