.. / CVE-2021-24407

Exploit for WordPress Jannah Theme <5.4.5 - Cross-Site Scripting (CVE-2021-24407)

Description:

WordPress Jannah theme before 5.4.5 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the ‘query’ POST parameter in its tie_ajax_search AJAX action.

Nuclei Template

View the template here CVE-2021-24407.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24407.yaml
Copy

References:

https://wpscan.com/vulnerability/fba9f010-1202-4eea-a6f5-78865c084153
https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-24407
https://github.com/ARPSyndicate/kenzer-templates