CVE-2021-24885

Severity
6.1MEDIUM
EPSS
0.2%
top 56.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateMay 24

Description

The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/yop_poll6.1.26.1.2
NVDyop-poll/yop-poll< 6.1.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fr5j-77mg-3779: The YOP Poll WordPress plugin before 62022-05-24
CVEList
YOP Poll < 6.1.2 - Reflected Cross-Site Scripting2021-10-25
CVE-2021-24885 (MEDIUM CVSS 6.1) | The YOP Poll WordPress plugin befor | cvebase.io