CVE-2021-24973
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
- Affected products
- Site Reviews
- Geminilabs Site Reviews
- < 5.17.3
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.3% (68th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-01-03
CVE-2021-24973 at NVD
1 known exploit for CVE-2021-24973
Proof-of-concept code and exploit modules indexed by Sploitus