Record summary

CVE-2021-24290 has a selected CVSS score of 6.1 (medium).

Description

There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticated attackers the ability to inject malicious JavaScript into pages.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List5.5.15 to ≤ 5.5.15affected
VulnCheckVersion data not supplied

References

3