CVE-2021-24908

CVE-2021-24908: Check & Log Email < 1.0.4 - Reflected Cross-Site Scripting

Vendor Unknown
Product Check & Log Email
Weakness CWE-79 · XSS
Published November 29, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

Key dates

02Disclosure timeline

November 29, 2021 CVE published
August 3, 2024 Record updated