CVE-2021-24756
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site…
Does this matter?
Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.
Description
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wp system log project/wp system log
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/0cea0717-8f54-4f1c-b3ee-aff7dd91bf59Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/0cea0717-8f54-4f1c-b3ee-aff7dd91bf59Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.