Lucene search

K
cvelistWPScanCVELIST:CVE-2021-25060
HistoryFeb 21, 2022 - 10:45 a.m.

CVE-2021-25060 Five Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Update to Stored XSS

2022-02-2110:45:47
CWE-79
WPScan
www.cve.org

0.001 Low

EPSS

Percentile

24.8%

The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact_information AJAX action, allowing any authenticated users, such as subscribers, to call them. Furthermore, due to the lack of sanitisation, it also lead to Stored Cross-Site Scripting issues

CNA Affected

[
  {
    "product": "Five Star Business Profile and Schema",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "2.1.7",
        "status": "affected",
        "version": "2.1.7",
        "versionType": "custom"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

24.8%

Related for CVELIST:CVE-2021-25060