.. / CVE-2021-39320

Exploit for WordPress Under Construction <1.19 - Cross-Site Scripting (CVE-2021-39320)

Description:

WordPress Under Construction plugin before 1.19 contains a cross-site scripting vulnerability. The plugin echoes out the raw value of $GLOBALS['PHP_SELF'] in the ucOptions.php file on certain configurations, including Apache+modPHP.

Nuclei Template

View the template here CVE-2021-39320.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-39320.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://wpscan.com/vulnerability/49ae1df0-d6d2-4cbb-9a9d-bf3599429875
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39320
https://nvd.nist.gov/vuln/detail/CVE-2021-39320
https://github.com/ARPSyndicate/kenzer-templates