nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24454 CVE-2021-24454
MEDIUM
YOP Poll < 6.2.8 - Stored Cross-Site Scripting
Record summary
CVE-2021-24454 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
YOP Poll | CVE List | 6.2.8 to < 6.2.8 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24454Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2021-24454Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
3wpscan.comConfirmation
https://wpscan.com/vulnerability/48ade7a5-5abb-4267-b9b6-13e31e1b3e91 in-spired.xyz
https://www.in-spired.xyz/discovering-wordpress-plugin-yop-polls-v6-2-7-stored-xss