Record summary

CVE-2021-24239 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments

CVE List3.7.0.1 to < 3.7.0.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Pie Register <3.7.0.1 - Cross-Site ScriptingCVSS 6.1

WordPress Pie Register plugin before 3.7.0.1 is susceptible to cross-site scripting. The plugin does not sanitize the invitaion_code GET parameter when outputting it in the Activation Code page. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site, which can allow the attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could lead to the execution of arbitrary script code in the context of the victim's browser, potentially allowing an attacker to steal sensitive information or perform actions on behalf of the victim.

Remediation

Fixed in version 3.7.0.1.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2021cvexsspie-registerwpwpscangenetechsolutionswordpressvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:genetechsolutions:pie_register:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3