Sploitus

CVE-2021-24487

1 known exploit for CVE-2021-24487

The St-Daily-Tip WordPress plugin through 4.7 does not have any CSRF check in place when saving its 'Default Text to Display if no tips' setting, and was also lacking sanitisation as well as escaping before outputting it the page. This could allow attacker to make logged in administrators set a malicious payload in it, leading to a Stored Cross-Site Scripting issue

Affected products
St-Daily-Tip
Sanskruti St-daily-tip
≤ 4.7
CVSS 3.1
8.8 HIGH
EPSS
0.6% (47th percentile)
Weakness
CWE-352, CWE-79
NVD status
Modified
Published
2021-10-25
CVE-2021-24487 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24487

Proof-of-concept code and exploit modules indexed by Sploitus