nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24508 CVE-2021-24508
MEDIUM
Smash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSS
Record summary
CVE-2021-24508 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Smash Balloon Social Post Feed | CVE List | 2.19.2 to < 2.19.2 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24508Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2021-24508Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/2b543740-d4b0-49b5-a021-454a3a72162f