Record summary

CVE-2021-24305 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.0affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24305Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 997 B

GitHub

PoC details
GitHubCVE-2021-24305Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 997 B

GitHub

PoC details

References

3