Record summary

CVE-2021-33851 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WordPress Customize Login Image Plugin

CVE ListVersion 3.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Customize Login Image <3.5.3 - Cross-Site ScriptingCVSS 5.4

WordPress Customize Login Image plugin prior to 3.5.3 contains a cross-site scripting vulnerability via the custom logo link on the Settings page. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing an attacker to execute malicious scripts in the context of the victim's browser.

Remediation

Update to the latest version of the WordPress Customize Login Image plugin (3.5.3) to mitigate the vulnerability.

WeaknessesCWE-79
Authors8authur
Template tagscvecve2021wpscanwordpresscustomize-login-imagewpauthenticatedwp-pluginxssapasionadosvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apasionados:customize_login_image:3.4:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2