nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24973 CVE-2021-24973
MEDIUM
Site Reviews < 5.17.3 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-24973 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Site Reviews | CVE List | 5.17.3 to < 5.17.3 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24973Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24973Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
3plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/2629821 wpscan.com
https://wpscan.com/vulnerability/0118f245-0e6f-44c1-9bdb-5b3a5d2403d6