.. / CVE-2021-33851

Exploit for WordPress Customize Login Image <3.5.3 - Cross-Site Scripting (CVE-2021-33851)

Description:

WordPress Customize Login Image plugin prior to 3.5.3 contains a cross-site scripting vulnerability via the custom logo link on the Settings page. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Nuclei Template

View the template here CVE-2021-33851.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-33851.yaml
Copy

References:

https://cybersecurityworks.com/zerodays/cve-2021-33851-stored-cross-site-scripting-in-wordpress-customize-login-image.html
https://nvd.nist.gov/vuln/detail/cve-2021-33851
https://wordpress.org/plugins/customize-login-image/
https://wpscan.com/vulnerability/c67753fb-9111-453e-951f-854c6ce31203
https://github.com/ARPSyndicate/kenzer-templates