Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24545

Опубликовано: 11 окт. 2021
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Средний

Описание

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wp_html_author_bio_project:wp_html_author_bio:*:*:*:*:*:wordpress:*:*
Версия до 1.2.0 (включая)

EPSS

Процентиль: 94%
0.13323
Средний

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.

EPSS

Процентиль: 94%
0.13323
Средний

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79