Vulnerability Details CVE-2021-24771
The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields when adding/editing a quote as admin, leading to Stored Cross-Site scripting issues when the quote is output in the "Quotes list" even when the unfiltered_html capability is disallowed
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2021-24771
-
cpe:2.3:a:inspirational_quote_rotator_project:inspirational_quote_rotator:-
-
cpe:2.3:a:inspirational_quote_rotator_project:inspirational_quote_rotator:1.0.0