CVE-2021-24508
Smash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
El plugin Smash Balloon Social Post Feed de WordPress versiones anteriores a 2.19.2, no sanea ni escapa del parámetro feedID POST en su acción feed_locator AJAX (disponible tanto para usuarios autenticados como no autenticados) antes de mostrar una versión truncada de la misma en el panel de administración, conllevando a un problema de tipo Cross-Site Scripting Almacenado no autenticado que se ejecutará en el contexto de un administrador conectado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-08-16 CVE Published
- 2024-05-29 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/2b543740-d4b0-49b5-a021-454a3a72162f | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Smashballoon Search vendor "Smashballoon" | Smash Balloon Social Post Feed Search vendor "Smashballoon" for product "Smash Balloon Social Post Feed" | < 2.19.2 Search vendor "Smashballoon" for product "Smash Balloon Social Post Feed" and version " < 2.19.2" | wordpress |
Affected
|