nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24124 CVE-2021-24124
MEDIUM
WP Shieldon 1.6.3 - Unauthenticated Cross-Site Scripting (XSS)
Record summary
CVE-2021-24124 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Shieldon | CVE List | 1.6.3 to ≤ 1.6.3 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24124Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24124Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/8d0eb0b4-0cc0-44e5-b720-90b01df3a6ee