ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2021-38340”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2021-38340
Published
2021-09-10
CVSS:
6.1
ShadowTrackr CVSS:
1.2
Summary:
The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter found in the ~/includes/add_product.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.