← back
CVE-2021-24245CWE-79

Stop Spammers < 2021.9 - Reflected Cross-Site Scripting (XSS)

38Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 5.7%
from disclosure to weapon14 days
Published on NVDMay 5
1st PoC+14d
exploitation probability
5.7%top 8% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.
Affected products
Trumani · Stop Spammers
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.