.. / CVE-2021-24342

Exploit for WordPress JNews Theme <8.0.6 - Cross-Site Scripting (CVE-2021-24342)

Description:

WordPress JNews theme before 8.0.6 contains a reflected cross-site scripting vulnerability. It does not sanitize the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*).

Nuclei Template

View the template here CVE-2021-24342.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24342.yaml
Copy

References:

https://wpscan.com/vulnerability/415ca763-fe65-48cb-acd3-b375a400217e
https://github.com/ARPSyndicate/cvemon
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2021-24342