Record summary

CVE-2021-25086 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Advanced Page Visit Counter – Advanced WordPress Visit Counter

CVE List6.1.2 to < 6.1.2affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-25086Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 636 B

GitHub

PoC details
GitHubCVE-2021-25086Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 636 B

GitHub

PoC details

References

2