CVE-2021-24719
MEDIUMEnfold < 4.8.4 - Reflected Cross-Site Scripting via Avia Page Builder
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24719. PoCs published by David Álvarez Robles.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in WordPress Theme Enfold versions prior to 4.8.4. The PoC shows how a crafted URL with a double-encoded payload can execute arbitrary JavaScript, such as logging document cookies.
Description
The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability is present on Enfold versions previous than 4.8.4 which use Avia Page Builder.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in WordPress Theme Enfold versions prior to 4.8.4. The PoC shows how a crafted URL with a double-encoded payload can execute arbitrary JavaScript, such as logging document cookies.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N