nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25067 CVE-2021-25067
MEDIUMNuclei
Landing Page Builder < 1.4.9.6 - Authenticated Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2021-25067 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages | CVE List | 1.4.9.6 to < 1.4.9.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLanding Page Builder < 1.4.9.6 - Cross-Site ScriptingCVSS 5.4
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.
Remediation
Fixed in version 1.4.9.6.
WeaknessesCWE-79
Authorstheamanrawat
Template tagscve2021cvexsswordpressauthenticatedwpscanwp-pluginwppage-builder-addpluginopsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:pluginops:landing_page:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/365007f0-61ac-4e81-8a3a-3a068f2c84bc https://wordpress.org/plugins/page-builder-add/ https://nvd.nist.gov/vuln/detail/CVE-2021-25067 https://github.com/kazet/wpgarlic https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
2wpscan.com
https://wpscan.com/vulnerability/365007f0-61ac-4e81-8a3a-3a068f2c84bc