CVE-2021-24561

CVE-2021-24561: WP SMS < 5.4.13 - Authenticated Stored Cross-Site Scripting

Vendor Unknown
Product WP SMS
Weakness CWE-79 · XSS
Published August 23, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

Key dates

02Disclosure timeline

August 23, 2021 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE