CVE-2021-24681

MEDIUM NUCLEI

Duplicate Page WP <4.4.2 - XSS

Title source: llm

Description

The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before outputting it, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Nuclei Templates (1)

Duplicate Page WordPress - Stored Cross-Site Scripting
MEDIUMVERIFIEDby theamanrawat

Scores

CVSS v3 4.8
EPSS 0.0030
EPSS Percentile 53.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
duplicatepro/duplicate_page < 4.4.2
Published Oct 11, 2021
Tracked Since Feb 18, 2026