CyberRota Analysis
AI analysis pending.
CVE
CVE-2021-24973
Severity
MEDIUM
CVSS
6.1
EPSS
1.31%
WordPress
Original NVD Description
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
Related CVEs
Other vulnerabilities affecting the same vendor(s)