CVE-2021-36823

Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (versions <= 6.8). Stored XSS possible via unsanitized input fields of the plugin settings, some of the payloads could make the frontend and the backend inaccessible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cusmin:absolutely_glamorous_custom_admin:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-09-23 17:15

Updated : 2021-09-29 20:01


NVD link : CVE-2021-36823

Mitre link : CVE-2021-36823


JSON object : View

Products Affected

cusmin

  • absolutely_glamorous_custom_admin
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')