nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24305 CVE-2021-24305
MEDIUM
Target First Plugin 2.0 - Unauthenticated Stored XSS via Licence Key
Record summary
CVE-2021-24305 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Target First PluginBrowse TargetFirst / Target First Plugin | CVE List | 2.0 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24305Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24305Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
3wpscan.comConfirmation
https://wpscan.com/vulnerability/4d55d1f5-a7b8-4029-942d-7a13e2498f64 targetfirst.com
https://www.targetfirst.com/