Vulnerabilities > CVE-2021-24477 - Unspecified vulnerability in Migrate Users Project Migrate Users 1.0.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its options, allowing the issue to be exploited via a CSRF attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |