CVE-2021-24213
GiveWP < 2.10.0 - Reflected Cross Site Scripting (XSS)
Record summary
CVE-2021-24213 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GiveWP – Donation Plugin and Fundraising PlatformBrowse GiveWP / GiveWP – Donation Plugin and Fundraising Platform | CVE List | 2.4.0 to < 2.4.0* | affected |
| 2.10.0 to < 2.10.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMGiveWP <= 2.9.7 - Cross-Site ScriptingCVSS 6.1
GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress versions before 2.10.0 is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in the admin Donors page.
Impact
Attackers can execute arbitrary scripts in authenticated admin browsers, potentially leading to session hijacking, privilege escalation, WordPress admin account takeover, malicious plugin installation, and website defacement.
Remediation
Update GiveWP plugin to version 2.10.0 or later.
Source: ProjectDiscovery