nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24792 CVE-2021-24792
MEDIUM
Shiny Buttons <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-24792 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a template (wpbtn_save_template function hooked to the init action), nor sanitise and escape them before outputting them in the admin dashboard, which allow unauthenticated users to add a malicious template and lead to Stored Cross-Site Scripting issues.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Shiny Buttons – CSS3 Button Generator for WordPress | CVE List | 1.1.0 to ≤ 1.1.0 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24792Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2021-24792Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/29514d8e-9d1c-4fb6-b378-f6b7374989ca