PT-2021-15759 · WordPress · Openid Connect Generic Client

Austin Bentley

·

Published

2021-05-05

·

Updated

2021-05-13

·

CVE-2021-24214

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: OpenID Connect Generic Client WordPress plugin versions 3.8.0 through 3.8.1
Description: The issue is related to a reflected Cross-Site Scripting problem. It occurs because the login error is not properly sanitized when output back in the login form. This issue can be exploited without authentication and with the default configuration.
Recommendations: For versions 3.8.0 and 3.8.1, update to a version that addresses this issue, as the current versions do not properly sanitise the login error, leading to a reflected Cross-Site Scripting issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24214

Affected Products

Openid Connect Generic Client