CVE-2021-24245

MEDIUM NUCLEI

Stop Spammers < 2021.9 - Reflected Cross-Site Scripting via Blocked Request Output

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-24245. PoCs published by Hosein Vita. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in WordPress Plugin Stop Spammers <= 2021.8. The payload is injected via the 'log' parameter in a POST request to wp-login.php, triggering arbitrary JavaScript execution when the accesskey event is activated.

Description

The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.

Exploits (1)

exploitdb WORKING POC
by Hosein Vita · textwebappsphp
https://www.exploit-db.com/exploits/49880

This exploit demonstrates a reflected XSS vulnerability in WordPress Plugin Stop Spammers <= 2021.8. The payload is injected via the 'log' parameter in a POST request to wp-login.php, triggering arbitrary JavaScript execution when the accesskey event is activated.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Stop Spammers <= 2021.8
No auth needed
Prerequisites: WordPress with Stop Spammers plugin <= 2021.8 installed · Attacker must lure victim to a crafted link or submit a malicious form
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress Stop Spammers <2021.9 - Cross-Site Scripting
MEDIUMby edoardottt

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://wpscan.com/vulnerability/5e7accd6-08dc-4c6e-9d19-73e2d7e97735

Scores

CVSS v3 6.1
EPSS 0.0572
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
trumani/stop_spammers < 2021.9
Published May 06, 2021
Tracked Since Feb 18, 2026