nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25107 CVE-2021-25107
MEDIUM
Form Store to DB < 1.1.1 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-25107 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back in the created entry, allowing unauthenticated attacker to perform Cross-Site Scripting attacks against admin
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Form Store to DB | CVE List | 1.1.1 to < 1.1.1 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2021-25107Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
GitHubCVE-2021-25107Curated repository PoCby yubsyStars: 112Not analyzed1 file
References
3plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/2657583 wpscan.com
https://wpscan.com/vulnerability/3999a1b9-df85-43b1-b412-dc8a6f71cc5d