Back to search
CVE-2021-24246
Published: May 5, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues
| Vendor | Product | Versions |
|---|---|---|
PureThemes | Workscout Core | affected 1.3.4 - < 1.3.4 |
PureThemes | WorkScout | affected 2.0.33 - < 2.0.33 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now