Record summary

CVE-2021-24979 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Paid Memberships Pro

CVE List2.6.6 to < 2.6.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPaid Memberships Pro < 2.6.6 - Cross-Site ScriptingCVSS 6.1

The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Impact

Attackers can inject malicious JavaScript via reflected XSS in the search parameter, potentially stealing administrator session cookies or accessing membership data.

Remediation

version 2.6.6

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2021cvewpwordpresswpscanwp-pluginxssauthenticatedstrangerstudiosvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/paid-memberships-pro/
FOFA: body=/wp-content/plugins/paid-memberships-pro/
Google: inurl:"/wp-content/plugins/paid-memberships-pro"

Source: ProjectDiscovery

References

3