nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25055 CVE-2021-25055
MEDIUMNuclei
FeedWordPress < 2022.0123 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-25055 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FeedWordPress | CVE List | 2022.0123 to < 2022.0123 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress FeedWordPress < 2022.0123 - Authenticated Cross-Site ScriptingCVSS 6.1
The plugin is affected by a cross-site scripting vulnerability within the "visibility" parameter.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data theft, and potential compromise of the affected WordPress website.
Remediation
Update to the latest version of the FeedWordPress plugin (version 2022.0123 or higher) to mitigate the vulnerability.
WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscve2021cvewordpressxsswp-pluginauthenticatedwpscanfeedwordpress_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:feedwordpress_project:feedwordpress:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/7ed050a4-27eb-4ecb-9182-1d8fa1e71571 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25055 https://plugins.trac.wordpress.org/changeset/2662665 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/2662665 wpscan.com
https://wpscan.com/vulnerability/7ed050a4-27eb-4ecb-9182-1d8fa1e71571