CVE-2021-24445
My Site Audit <= 1.2.4 - Authenticated Stored Cross-Site Scripting (XSS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
El plugin de WordPress My Site Audit versiones hasta 1.2.4, no sanea o escapa del campo Audit Name cuando se crea una auditoría, permitiendo a usuarios con altos privilegios ajustar cargas útiles de JavaScript en ellas, incluso cuando la capacidad unfiltered_html está deshabilitada, conllevando a un problema de tipo Cross-Site Scripting Almacenado autenticado.
The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit, allowing high privilege users to set JavaScript payloads in them, even when he unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-07-19 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/d60634a3-ca39-43be-893b-ff9ba625360f | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Draftpress Search vendor "Draftpress" | My Site Audit Search vendor "Draftpress" for product "My Site Audit" | <= 1.2.4 Search vendor "Draftpress" for product "My Site Audit" and version " <= 1.2.4" | wordpress |
Affected
|