Record summary

CVE-2021-25107 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.

Description

The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2

Affected products and versions

1
ProductSourceVersion rangeStatus

Form Store to DB

CVE List1.1.1 to < 1.1.1affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-25107Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 1.4 KiB

GitHub

PoC details
GitHubCVE-2021-25107Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 1.4 KiB

GitHub

PoC details

References

3