SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24298

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

MEDIUM 6.1EPSS 3.45%

Does this matter?

Lower severity and a low EPSS score (3.45%). Track it; it rarely justifies an emergency change on its own.

Description

The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
3.45% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
ibenic/simple giveaways
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.