← back
CVE-2021-25112CWE-79

WHMCS Bridge < 6.4b - Reflected Cross-Site Scripting (XSS)

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 2.2%
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
Affected products
Unknown · WHMCS Bridge