PT-2021-15842 · WordPress · Target First Wordpress Plugin
Darkpills
+1
·
Published
2021-05-24
·
Updated
2021-05-28
·
CVE-2021-24305
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Target First WordPress Plugin version 2.0
Description
The issue is related to a critical unauthenticated stored XSS vulnerability. An attacker can modify the licence key value by sending a POST request to any URL with the
weeWzKey parameter, which is then saved as the weeID option without proper sanitization.Recommendations
For version 2.0, consider disabling the licence key modification functionality until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to any URL that accepts the
weeWzKey parameter to minimize the risk of exploitation. Avoid using the weeWzKey parameter in POST requests until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Target First Wordpress Plugin