CVE-2021-24973: fallo en Site Reviews
Site Reviews < 5.17.3 - Unauthenticated Stored Cross-Site Scripting
Publicada el · Actualizada el
3Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 1.3%
probabilidad de explotación
1.3%top 30% de las CVE
explotación observada
noninguna fuente lo reporta
The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_action AJAX action (available to unauthenticated and any authenticated users), allowing them to perform Cross-Site Scripting attacks against logged in admins viewing the Tool dashboard of the plugin
Productos afectados
Unknown · Site ReviewsCVEs relacionadas — Site Reviews
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-1232HIGHSite Reviews < 7.2.5 - Unauthenticated Stored XSSEPSS 1.9%CVE-2021-24603—Site Reviews < 5.13.1 - Authenticated Stored XSSEPSS 0.6%CVE-2024-3050CRITICALSite Reviews < 7.0.0 - IP SpoofingEPSS 0.6%CVE-2023-1525MEDIUMSite Reviews < 6.7.1 - Admin+ Stored XSSEPSS 0.5%CVE-2026-82925HIGHSite Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form SignatureEPSS 0.5%