nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24975 CVE-2021-24975
MEDIUM
NextScripts: Social Networks Auto-Poster < 4.3.24 - Unauthenticated Stored XSS
Record summary
CVE-2021-24975 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests before outputting them in the related admin dashboard, leading to an Unauthenticated Stored Cross-Site Scripting issue
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NextScripts: Social Networks Auto-Poster | CVE List | 4.3.24 to < 4.3.24 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-24975Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-24975Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
3plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/2650138 wpscan.com
https://wpscan.com/vulnerability/b99dae3d-8230-4427-adc5-4ef9cbfb8ba1