PT-2021-16004 · WordPress · Hostel Wordpress Plugin

Abisheik M

·

Published

2021-08-02

·

Updated

2021-08-10

·

CVE-2021-24481

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Any Hostname WordPress plugin versions 1.0.0 through 1.0.6
Description The issue arises from the lack of sanitization or escaping of the "Allowed hosts" setting in the plugin, leading to an authenticated stored XSS issue. High privilege users can set XSS payloads in this setting.
Recommendations For versions 1.0.0 through 1.0.6, as a temporary workaround, consider restricting access to the "Allowed hosts" setting to prevent high privilege users from setting XSS payloads until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24481

Affected Products

Hostel Wordpress Plugin