Record summary

CVE-2021-24213 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-Site Scripting vulnerability inside of the administration panel, via the 's' GET parameter on the Donors page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

GiveWP – Donation Plugin and Fundraising Platform

Browse GiveWP / GiveWP – Donation Plugin and Fundraising Platform
CVE List2.4.0 to < 2.4.0*affected
2.10.0 to < 2.10.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGiveWP <= 2.9.7 - Cross-Site ScriptingCVSS 6.1

GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress versions before 2.10.0 is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in the admin Donors page.

Impact

Attackers can execute arbitrary scripts in authenticated admin browsers, potentially leading to session hijacking, privilege escalation, WordPress admin account takeover, malicious plugin installation, and website defacement.

Remediation

Update GiveWP plugin to version 2.10.0 or later.

WeaknessesCWE-79
AuthorsShivam Kamboj
Template tagscvecve2021wordpresswpwp-plugingiveauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3