SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24176

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

MEDIUM 5.4EPSS 2.04%

Does this matter?

Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.

Description

The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output in the dashboard, which leads to executing arbitrary JavaScript code in the WordPress dashboard.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
2.04% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jh 404 logger project/jh 404 logger
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.