nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24350 CVE-2021-24350
MEDIUM
Visitors <= 0.3 - Unauthenticated Stored Cross-Site Scripting (XSS)
Record summary
CVE-2021-24350 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Visitors | CVE List | 0.3 to ≤ 0.3 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24350Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2021-24350Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.comConfirmation
https://wpscan.com/vulnerability/06f1889d-8e2f-481a-b91b-3a8008e00ffc