Record summary

CVE-2021-25008 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Code Snippets

CVE List2.14.3 to < 2.14.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMThe Code Snippets WordPress Plugin < 2.14.3 - Cross-Site ScriptingCVSS 6.1

The Wordpress plugin Code Snippets before 2.14.3 does not escape the snippets-safe-mode parameter before reflecting it in attributes, leading to a reflected cross-site scripting issue.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update the Code Snippets WordPress Plugin to version 2.14.3 or later to mitigate the vulnerability.

WeaknessesCWE-79
Authorscckuailong
Template tagscvecve2021authenticatedwpscanxsswpwordpresswp-plugincodesnippetsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:codesnippets:code_snippets:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2