CVE-2021-24468
Leaflet Map < 3.0.0 - Contributor+ Stored XSS
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
02 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScript code or HTML, which could allow users with a role as low as Contributors to exploit stored XSS issues
Affected products
Unknown · Leaflet Map