CVE-2021-33851
WordPress Customize Login Image <3.5.3 - Cross-Site Scripting
Record summary
CVE-2021-33851 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicle for the attack. The XSS payload given in the "Custom logo link" executes whenever the user opens the Settings Page of the "Customize Login Image" Plugin.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WordPress Customize Login Image Plugin | CVE List | Version 3.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Customize Login Image <3.5.3 - Cross-Site ScriptingCVSS 5.4
WordPress Customize Login Image plugin prior to 3.5.3 contains a cross-site scripting vulnerability via the custom logo link on the Settings page. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.
Impact
Successful exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing an attacker to execute malicious scripts in the context of the victim's browser.
Remediation
Update to the latest version of the WordPress Customize Login Image plugin (3.5.3) to mitigate the vulnerability.
Source: ProjectDiscovery