peter bassill · operator
$ cve CVE-2021-24247 JSON

CVE-2021-24247 EXPLOIT

5.4
MEDIUM · CVSS 3.1 · EPSS 4.7% (pctl 92)

Patch early

A public exploit exists.

Description

The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS4.68% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-05-06
Last modified2026-06-17

Affected (1)

VendorProduct
mooveagencycontact form check tester

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD