Record summary

CVE-2021-24454 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

YOP Poll

CVE List6.2.8 to < 6.2.8affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24454Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 928 B

GitHub

PoC details
GitHubCVE-2021-24454Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 928 B

GitHub

PoC details

References

3