Record summary

CVE-2021-24237 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List1.3.1 to < 1.3.1affected
CVE List1.2.4 to < 1.2.4affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24237Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 654 B

GitHub

PoC details
GitHubCVE-2021-24237Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 654 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Realteo <=1.2.3 - Cross-Site ScriptingCVSS 6.1

WordPress Realteo plugin 1.2.3 and prior contains an unauthenticated reflected cross-site scripting vulnerability due to improper sanitization of keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.

Remediation

Update to the latest version of the WordPress Realteo plugin (>=1.2.4) which includes a fix for the Cross-Site Scripting vulnerability.

WeaknessesCWE-79
Authors0x_Akoko
Template tagscve2021cverealteoxsswordpresspluginwpscanintrusivepurethemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:purethemes:findeo:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

7