CVE-2021-24298
Simple Giveaways < 2.36.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-24298 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple Giveaways – Grow your business, email lists and traffic with contestsBrowse Igor Benic / Simple Giveaways – Grow your business, email lists and traffic with contests | CVE List | 2.36.2 to < 2.36.2 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24298Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24298Curated repository PoCby yubsyStars: 112Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Simple Giveaways <2.36.2 - Cross-Site ScriptingCVSS 6.1
WordPress Simple Giveaways plugin before 2.36.2 contains a cross-site scripting vulnerability via the method and share GET parameters of the Giveaway pages, which are not sanitized, validated, or escaped before being output back in the pages.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential theft of sensitive information or unauthorized actions.
Remediation
Update to the latest version of the WordPress Simple Giveaways plugin (2.36.2 or higher) to mitigate the vulnerability.
Source: ProjectDiscovery