CVE Database
/

CVE-2021-24653

Back to search

CVE-2021-24653

Published: Oct 25, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

VendorProductVersions

Unknown

Cookie Bar

affected
1.8.9 - < 1.8.9

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now