CVE-2021-24545

MEDIUM LAB

WP Html Author Bio < 1.2.0 - XSS

Title source: rule
STIX 2.1

Description

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

Exploits (2)

nomisec WORKING POC 2 stars
by V35HR4J · poc
https://github.com/V35HR4J/CVE-2021-24545
nomisec WORKING POC
by dnr6419 · poc
https://github.com/dnr6419/CVE-2021-24545

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/64267134-9d8c-4e0c-b24f-d18692a5775e

Scores

CVSS v3 5.4
EPSS 0.1332
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:5.7.0-php7.4-apache

Details

CWE
CWE-79
Status published
Products (1)
wp_html_author_bio_project/wp_html_author_bio < 1.2.0
Published Oct 11, 2021
Tracked Since Feb 18, 2026