CVE-2021-24286
MEDIUM NUCLEIRedirect 404 to Parent < 1.3.1 - Reflected Cross-Site Scripting via Tab Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24286. PoCs published by 0xB9. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the WordPress plugin 'Redirect 404 to Parent' version 1.3.0. The vulnerability is triggered via the 'tab' parameter in the admin panel, allowing arbitrary JavaScript execution.
Description
The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the WordPress plugin 'Redirect 404 to Parent' version 1.3.0. The vulnerability is triggered via the 'tab' parameter in the admin panel, allowing arbitrary JavaScript execution.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N