.. / CVE-2021-24245

Exploit for WordPress Stop Spammers <2021.9 - Cross-Site Scripting (CVE-2021-24245)

Description:

WordPress Stop Spammers plugin before 2021.9 contains a reflected cross-site scripting vulnerability. It does not escape user input when blocking requests (such as matching a spam word), thus outputting it in an attribute after sanitizing it to remove HTML tags.

Nuclei Template

View the template here CVE-2021-24245.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24245.yaml
Copy

References:

https://packetstormsecurity.com/files/162623/WordPress-Stop-Spammers-2021.8-Cross-Site-Scripting.html
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-24245
http://packetstormsecurity.com/files/162623/WordPress-Stop-Spammers-2021.8-Cross-Site-Scripting.html
https://wpscan.com/vulnerability/5e7accd6-08dc-4c6e-9d19-73e2d7e97735