CVE Database
/

CVE-2021-24246

Back to search

CVE-2021-24246

Published: May 5, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The Workscout Core WordPress plugin before 1.3.4, used by the WorkScout Theme did not sanitise the chat messages sent via the workscout_send_message_chat AJAX action, leading to Stored Cross-Site Scripting and Cross-Frame Scripting issues

VendorProductVersions

PureThemes

Workscout Core

affected
1.3.4 - < 1.3.4

PureThemes

WorkScout

affected
2.0.33 - < 2.0.33

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now