CVE Feed

    Dashboard / CVE / CVE-2021-24330

    CVE-2021-24330

    The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not sanitise its facebook_pixel_id and google_analytics_id settings, allowing high privilege users to set XSS payload in them, which will either be executed on pages generated by the plugin, or the whole website depending on the settings used.

    Published:Jun 1, 2021
    Last Modified:Nov 21, 2024
    EPS:Jun 1, 2021
    EPSS Score:0.00186
    CVSS Score:4.8

    Affected Products

    Vendor
    Cartflows
    Product
    Cartflows

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High