Sploitus

CVE-2021-24973

1 known exploit for CVE-2021-24973

The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin

Affected products
Site Reviews
Geminilabs Site Reviews
< 5.17.3
Fix
Available
CVSS 3.1
6.1 MEDIUM
EPSS
1.3% (68th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2022-01-03
CVE-2021-24973 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24973

Proof-of-concept code and exploit modules indexed by Sploitus