Sploitus

CVE-2021-24408

1 known exploit for CVE-2021-24408

The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.

Affected products
Prismatic
Plugin-planet Prismatic
< 2.8
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.6% (48th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2021-07-12
CVE-2021-24408 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24408

Proof-of-concept code and exploit modules indexed by Sploitus