Security Advisory

CVE-2024-10815

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-01-09 06:00:04
Last updated 2025-01-09 16:01:25
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers