VulnerabilityModified
CVE-2021-24176
The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
MEDIUM 5.4EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jh 404 logger project/jh 404 logger
- Source
- contact@wpscan.com
References
- https://ganofins.com/blog/my-first-cve-2021-24176/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585Exploit, Third Party Advisory
- https://ganofins.com/blog/my-first-cve-2021-24176/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.