Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-24570
HistoryNov 01, 2021 - 9:15 a.m.

Cross site scripting

2021-11-0109:15:00
PRIOn knowledge base
www.prio-n.com
3

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%

The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not escaped before being output in an attribute when editing a Button, leading to a Stored Cross-Site Scripting issue as well.

CPENameOperatorVersion
accept_donations_with_paypallt1.3.1

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%

Related for PRION:CVE-2021-24570