PoC Index

CVE-2021-24211

MEDIUM 5.4EPSS 0.6%

The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the title field on the settings page. By exploiting that an attacker will be able to execute JavaScript code in the user's browser.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
0.63% chance of exploitation in the next 30 days, 48th percentile
Published
2021-04-05
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related