Record summary

CVE-2021-24926 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)ExploitDB exploitby Ceylan BOZOĞULLARINDANNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Domain Check <1.0.17 - Cross-Site ScriptingCVSS 6.1

WordPress Domain Check plugin before 1.0.17 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the domain parameter before outputting it back in the page.

Impact

Attackers can inject malicious JavaScript via reflected XSS in the domain parameter, potentially stealing administrator session cookies or performing administrative actions.

Remediation

Update to WordPress Domain Check plugin version 1.0.17 or later to mitigate the vulnerability.

WeaknessesCWE-79
Authorscckuailong
Template tagscvecve2021wpscanxsswpwordpresswp-pluginauthenticateddomaincheckpluginvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:domaincheckplugin:domain_check:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2