Vulnerabilities > CVE-2021-24954 - Unspecified vulnerability in Profilepress User Registration, Login Form, User Profile & Membership 3.2.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape the ppress_cc_data parameter before outputting it back in an attribute of an admin dashboard page, leading to a Reflected Cross-Site Scripting issue
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |