vendor:
Domain Check
by:
Ceylan Bozogullarindan
6.1
CVSS
MEDIUM
Reflected Cross-Site Scripting (XSS)
79
CWE
Product Name: Domain Check
Affected Version From: 1.0.0
Affected Version To: 1.0.15
Patch Exists: YES
Related CWE: CVE-2021-24926
CPE: 2.3:a:wordpress:domain_check:1.0.16
Tags: wpscan,cve,cve2021,xss,wp,wordpress,wp-plugin,authenticated
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Nuclei Metadata: {'max-request': 2, 'framework': 'wordpress', 'vendor': 'domaincheckplugin', 'product': 'domain_check'}
Platforms Tested: Linux
2021
WordPress Plugin Domain Check 1.0.16 – Reflected Cross-Site Scripting (XSS) (Authenticated)
An authenticated user is able to inject arbitrary Javascript or HTML code to the "Domain Check Profile" interface available in settings page of the plugin, due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the administrators. The plugin versions prior to 1.0.16 are affected by this vulnerability.
Mitigation:
Upgrade to the latest version of the plugin (1.0.16) to mitigate this vulnerability.