Record summary

CVE-2021-24387 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.1.1 to < 3.1.1affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2021-24387Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 663 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Pro Real Estate 7 Theme <3.1.1 - Cross-Site ScriptingCVSS 6.1

WordPress Pro Real Estate 7 theme before 3.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the ct_community parameter in its search listing page before outputting it back.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update WordPress Pro Real Estate 7 Theme to version 3.1.1 or later to mitigate the vulnerability.

WeaknessesCWE-79
Authorssuman_kar
Template tagscvecve2021xsswordpresswpscancontempothemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:contempothemes:real_estate_7:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3