CVE Database
/

CVE-2021-24443

Back to search

CVE-2021-24443

Published: Aug 2, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example.

VendorProductVersions

Unknown

Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress

affected
1.0.7 - < 1.0.7

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now