The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting when outputting it in the backend and frontend, leading to an Authenticated Stored Cross-Site Scripting issue
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 05:53
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://wpscan.com/vulnerability/309296d4-c397-4fc7-85fb-a28b5b5b6a8d - Exploit, Third Party Advisory | 
Information
                Published : 2021-08-30 15:15
Updated : 2024-11-21 05:53
NVD link : CVE-2021-24593
Mitre link : CVE-2021-24593
CVE.ORG link : CVE-2021-24593
JSON object : View
Products Affected
                business_hours_indicator_project
- business_hours_indicator
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
