Alojapro Booking Engine [alojapro-widget] < 1.1.16
unknown
[en] The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.1.16
- Fixed in:
- 1.1.16
- Disclosed:
- Sep 20, 2021
CVE-2021-24530 on NVD →
Alojapro Widget <= 1.1.15 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.1.15
- Fixed in:
- 1.1.16
- Disclosed:
- Jul 29, 2021
CVE-2021-24530 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database