PT-2026-39503 · Wpsymposiumpro · Wp Symposium Pro

Murat Demirci

·

Published

2026-05-10

·

Updated

2026-05-10

·

CVE-2021-47927

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps admin forum add name parameter, which are stored and executed when the forum is accessed.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47927

Affected Products

Wp Symposium Pro