vendor:
Stop Spammers
by:
Hosein Vita
6.1
CVSS
MEDIUM
Reflected Cross-site Scripting (XSS)
79
CWE
Product Name: Stop Spammers
Affected Version From: <= 2021.8
Affected Version To: <= 2021.8
Patch Exists: YES
Related CWE: CVE-2021-24245
CPE: 2.3:a:wordpress:stop_spammer_registrations_plugin:2021.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows-Ubuntu
2021
WordPress Plugin Stop Spammers 2021.8 – ‘log’ Reflected Cross-site Scripting (XSS)
Reflected cross-site scripting (XSS) vulnerabilities in 'Stop Spammers <= 2021.8' allow remote attackers to run arbitary javascript by entering a malicious payload in the username field.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.