CVE-2021-24570
Paypal Donation < 1.3.1 - CSRF to Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.
El plugin Accept Donations with PayPal de WordPress versiones anteriores a 1.3.1, ofrece una función para crear botones de donación, que internamente son posts. El proceso para crear un nuevo botón carece de una comprobación de tipo CSRF. Un atacante podría usar esto para que un administrador autenticado cree un nuevo botón. Además, uno de los campos Button no se escapa antes de ser emitido en un atributo cuando se edita un botón, conllevando también a un problema de tipo Cross-Site Scripting Almacenado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-10-04 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/5c73754c-eebe-424a-9d3b-ca83eb53bf87 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://plugins.trac.wordpress.org/changeset/2608073 | 2022-11-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpplugin Search vendor "Wpplugin" | Accept Donations With Paypal Search vendor "Wpplugin" for product "Accept Donations With Paypal" | < 1.3.1 Search vendor "Wpplugin" for product "Accept Donations With Paypal" and version " < 1.3.1" | wordpress |
Affected
|