.. / CVE-2021-25008

Exploit for The Code Snippets WordPress Plugin < 2.14.3 - Cross-Site Scripting (CVE-2021-25008)

Description:

The Wordpress plugin Code Snippets before 2.14.3 does not escape the snippets-safe-mode parameter before reflecting it in attributes, leading to a reflected cross-site scripting issue.

Nuclei Template

View the template here CVE-2021-25008.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-25008.yaml
Copy

References:

https://wpscan.com/vulnerability/cb232354-f74d-48bb-b437-7bdddd1df42a
https://nvd.nist.gov/vuln/detail/CVE-2021-25008
https://github.com/ARPSyndicate/cvemon
https://github.com/ARPSyndicate/kenzer-templates