CVE-2021-24509
Last modified
CVE-2021-24509 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.. EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| A3rev | Page View Count | < 2.4.9 |
References
- https://wpscan.com/vulnerability/06df2729-21da-4c22-ae1e-dda1f15bdf8fExploit, Third Party Advisory
- https://wpscan.com/vulnerability/06df2729-21da-4c22-ae1e-dda1f15bdf8fExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-24509?
How severe is CVE-2021-24509?
How do I fix CVE-2021-24509?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-24503The Popular Brand Icons – Simple Icons WordPress plugin befo…5.4
- CVE-2021-24504The WP LMS – Best WordPress LMS Plugin WordPress plugin thro…6.1
- CVE-2021-24505The Forms WordPress plugin before 1.12.3 did not sanitise it…5.4
- CVE-2021-24506The Slider Hero with Animation, Video Background & Intro Mak…8.8
- CVE-2021-24507The Astra Pro Addon WordPress plugin before 3.5.2 did not pr…9.8
- CVE-2021-24508The Smash Balloon Social Post Feed WordPress plugin before 2…6.1
- CVE-2021-2451Vulnerability in the Oracle Outside In Technology product of…7.5
- CVE-2021-24510The MF Gig Calendar WordPress plugin before 1.2 does not san…6.1
- CVE-2021-24511The fetch_product_ajax functionality in the Product Feed on …7.2
- CVE-2021-24512The Video Posts Webcam Recorder WordPress plugin before 3.2.…5.4
- CVE-2021-24513The Form Builder | Create Responsive Contact Forms WordPress…5.4
- CVE-2021-24514The Visual Form Builder WordPress plugin before 3.0.4 does n…4.8
Are you affected by CVE-2021-24509?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
