CVE-2021-24593
Business Hours Indicator < 2.3.5 - Authenticated Stored XSS
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
Affected products
Unknown · Business Hours Indicator