CVE-2021-24410
Telugu Bible Verse Daily <= 1.0 - CSRF to Stored XSS
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issues
Affected products
Unknown · తెలుగు బైబిల్ వచనములుWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →