CVE-2021-24950
Insight Core <= 1.0 - Subscriber+ PHP Object Injection & Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the response. As a result, it could allow users with a role as low as Subscriber to perform PHP Object Injection, as well as Stored Cross-Site Scripting attacks
El plugin Insight Core de WordPress versiones hasta 1.0, no presenta ninguna comprobación de autorización y CSRF en el insight_customizer_options_import (disponible para cualquier usuario autenticado), no comprueba la entrada del usuario antes de pasarla a unserialize(), ni la sanea y escapa antes de mostrarla en la respuesta. Como resultado, podría permitir a usuarios con un rol tan bajo como el de suscriptor llevar a cabo una inyección de objetos de PHP, así como ataques de tipo Cross-Site Scripting Almacenado
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-12-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/01d430ea-ef85-4529-9ae4-c1f70016bb75 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Thememove Search vendor "Thememove" | Insight Core Search vendor "Thememove" for product "Insight Core" | 1.0 Search vendor "Thememove" for product "Insight Core" and version "1.0" | wordpress |
Affected
|