Record summary

CVE-2021-24245 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2021.9 to < 2021.9affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Stop Spammers 2021.8 - 'log' Reflected Cross-site Scripting (XSS)ExploitDB exploitby Hosein VitaNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Stop Spammers <2021.9 - Cross-Site ScriptingCVSS 6.1

WordPress Stop Spammers plugin before 2021.9 contains a reflected cross-site scripting vulnerability. It does not escape user input when blocking requests (such as matching a spam word), thus outputting it in an attribute after sanitizing it to remove HTML tags.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential theft of sensitive information or unauthorized actions.

Remediation

Update to the latest version of the WordPress Stop Spammers plugin (2021.9 or later) to mitigate this vulnerability.

WeaknessesCWE-79
Authorsedoardottt
Template tagscve2021cvewpscanwordpressxsswp-pluginpacketstormtrumanivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:trumani:stop_spammers:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3