Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) | 3.1.11 ~ 3.1.11 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The ProfilePress plugin for WordPress before 3.1.11 is vulnerable to unauthenticated reflected cross-site scripting (XSS) via the tabbed login/register widget due to improper escaping of user input. Attackers can inject arbitrary JavaScript via the tabbed-login-name parameter. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24522.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet