Record summary

CVE-2021-25067 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages

CVE List1.4.9.6 to < 1.4.9.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLanding Page Builder < 1.4.9.6 - Cross-Site ScriptingCVSS 5.4

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Fixed in version 1.4.9.6.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscve2021cvexsswordpressauthenticatedwpscanwp-pluginwppage-builder-addpluginopsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:pluginops:landing_page:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2