CVE-2021-25008
Code Snippets < 2.14.3 - Reflected Cross-Site Scripting
Record summary
CVE-2021-25008 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Code Snippets | CVE List | 2.14.3 to < 2.14.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMThe Code Snippets WordPress Plugin < 2.14.3 - Cross-Site ScriptingCVSS 6.1
The Wordpress plugin Code Snippets before 2.14.3 does not escape the snippets-safe-mode parameter before reflecting it in attributes, leading to a reflected cross-site scripting issue.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, leading to potential data theft, session hijacking, or defacement.
Remediation
Update the Code Snippets WordPress Plugin to version 2.14.3 or later to mitigate the vulnerability.
Source: ProjectDiscovery