.. / CVE-2021-24387

Exploit for WordPress Pro Real Estate 7 Theme <3.1.1 - Cross-Site Scripting (CVE-2021-24387)

Description:

WordPress Pro Real Estate 7 theme before 3.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the ct_community parameter in its search listing page before outputting it back.

Nuclei Template

View the template here CVE-2021-24387.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24387.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://contempothemes.com/wp-real-estate-7/changelog/
https://wpscan.com/vulnerability/27264f30-71d5-4d2b-8f36-4009a2be6745
https://nvd.nist.gov/vuln/detail/CVE-2021-24387
https://cxsecurity.com/issue/WLB-2021070041