CVE-2021-24443
Published: Aug 2, 2021
Modified: Aug 3, 2024
Description
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress | affected 1.0.7 - < 1.0.7 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now