plugin

Project Status Vulnerabilities

1 known security issue reported for the Project Status WordPress plugin. Most recent disclosed Jul 24, 2021.

1 medium

Running Project Status on your site? Check whether your installed version is affected.

Scan your site free

Project Status <= 1.6 - Reflected Cross-Site Scripting

medium

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

CVSS:
5.4
Affected:
up to 1.6
Fix:
No patched version reported
Disclosed:
Jul 24, 2021

CVE-2021-24558 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database