PT-2021-15842 · WordPress · Target First Wordpress Plugin

Darkpills

+1

·

Published

2021-05-24

·

Updated

2021-05-28

·

CVE-2021-24305

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Target First WordPress Plugin version 2.0
Description The issue is related to a critical unauthenticated stored XSS vulnerability. An attacker can modify the licence key value by sending a POST request to any URL with the weeWzKey parameter, which is then saved as the weeID option without proper sanitization.
Recommendations For version 2.0, consider disabling the licence key modification functionality until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to any URL that accepts the weeWzKey parameter to minimize the risk of exploitation. Avoid using the weeWzKey parameter in POST requests until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24305

Affected Products

Target First Wordpress Plugin