PT-2021-15971 · WordPress · Youzify

Fergustr4N

+1

·

Published

2021-08-02

·

Updated

2021-08-10

·

CVE-2021-24443

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin versions prior to 1.0.7
Description The issue concerns the About Me widget's Biography field, which does not properly sanitise input. This allows any authenticated user to set Cross-Site Scripting payloads, potentially leading to unauthorised access to the admin side of the blog when an admin views the affected user profile.
Recommendations For versions prior to 1.0.7, update to version 1.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the About Me widget's Biography field to prevent low-privilege users from setting malicious payloads.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24443

Affected Products

Youzify