CVE-2021-24737

The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*

History

15 Oct 2021, 16:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 4.8
CPE cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*
References (MISC) https://wpscan.com/vulnerability/f51a350c-c46d-4d52-b787-762283625d0b - (MISC) https://wpscan.com/vulnerability/f51a350c-c46d-4d52-b787-762283625d0b - Exploit, Third Party Advisory

11 Oct 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-11 11:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-24737

Mitre link : CVE-2021-24737

CVE.ORG link : CVE-2021-24737


JSON object : View

Products Affected

gvectors

  • wpdiscuz
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')