PT-2026-39503 · Wpsymposiumpro · Wp Symposium Pro
Murat Demirci
·
Published
2026-05-10
·
Updated
2026-05-10
·
CVE-2021-47927
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps admin forum add name parameter, which are stored and executed when the forum is accessed.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Symposium Pro