Skip to content

Known CVE

The Code Snippets WordPress Plugin < 2.14.3 - Cross-Site Scripting

The Wordpress plugin Code Snippets before 2.14.3 does not escape the snippets-safe-mode parameter before reflecting it in attributes, leading to a reflected cross-site scripting issue.

CVE-2021-25008

Medium2021CVSS 6.1CWE-79

cve2021 · authenticated · wpscan · xss · wp · wordpress · wp-plugin · codesnippets

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website