PT-2021-16004 · WordPress · Hostel Wordpress Plugin
Abisheik M
·
Published
2021-08-02
·
Updated
2021-08-10
·
CVE-2021-24481
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Any Hostname WordPress plugin versions 1.0.0 through 1.0.6
Description
The issue arises from the lack of sanitization or escaping of the "Allowed hosts" setting in the plugin, leading to an authenticated stored XSS issue. High privilege users can set XSS payloads in this setting.
Recommendations
For versions 1.0.0 through 1.0.6, as a temporary workaround, consider restricting access to the "Allowed hosts" setting to prevent high privilege users from setting XSS payloads until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hostel Wordpress Plugin