VulnerabilityModified
CVE-2021-24214
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue.
MEDIUM 6.1EPSS 1.63%
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- daggerhartlab/openid connect generic client
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/31cf0dfb-4025-4898-a5f4-fc7115565a10Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/31cf0dfb-4025-4898-a5f4-fc7115565a10Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.