Record summary

CVE-2021-24508 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Smash Balloon Social Post Feed

CVE List2.19.2 to < 2.19.2affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24508Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 1.4 KiB

GitHub

PoC details
GitHubCVE-2021-24508Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 1.4 KiB

GitHub

PoC details

References

2