CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.4. It affects WordPress, Java. It may be remotely exploitable.
CVE
CVE-2021-24136
Severity
MEDIUM
CVSS
5.4
EPSS
0.82%
WordPress Java
Original NVD Description
Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL
Related CVEs
Other vulnerabilities affecting the same vendor(s)