Record summary

CVE-2021-24389 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.

Description

The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly sanitize the foodbakery_radius parameter before outputting it back in the response, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List2.2 to < 2.2affected
CVE List2.2 to < 2.2affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2021-24389Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 1.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress FoodBakery <2.2 - Cross-Site ScriptingCVSS 6.1

WordPress FoodBakery before 2.2 contains an unauthenticated reflected cross-site scripting vulnerability. It does not properly sanitize the foodbakery_radius parameter before outputting it back in the response.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update the WordPress FoodBakery plugin to version 2.2 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2021cvewordpressxsswp-pluginwpscanchimpgroupvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:chimpgroup:foodbakery:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2