CVE-2021-24287
MEDIUM NUCLEISelect All Categories and Taxonomies < 1.3.2 - Reflected XSS via Tab Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24287. PoCs published by 0xB9. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the WordPress plugin 'Select All Categories and Taxonomies' version 1.3.1. The vulnerability is triggered via the 'tab' parameter in the admin panel, allowing arbitrary JavaScript execution.
Description
The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before 1.3.2 did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the WordPress plugin 'Select All Categories and Taxonomies' version 1.3.1. The vulnerability is triggered via the 'tab' parameter in the admin panel, allowing arbitrary JavaScript execution.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N