Vulnerabilities > CVE-2021-24286 - Unspecified vulnerability in Mooveagency Redirect 404 to Parent
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
Vulnerable Configurations
References
- http://packetstormsecurity.com/files/164328/WordPress-Redirect-404-To-Parent-1.3.0-Cross-Site-Scripting.html
- http://packetstormsecurity.com/files/164328/WordPress-Redirect-404-To-Parent-1.3.0-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/b9a535f3-cb0b-46fe-b345-da3462584e27
- https://wpscan.com/vulnerability/b9a535f3-cb0b-46fe-b345-da3462584e27