← volver
CVE-2021-24313

WP Prayer < 1.6.2 - Authenticated Stored Cross-Site Scripting (XSS)

EPSS 0.7%CWE-79
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
01 jun 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.
Productos afectados
Unknown · WP Prayer