CVE-2021-24833
Estado: ModificadaMedia (5.4)—
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of question and answer text parameters in Create Poll module.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.12%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- https://plugins.trac.wordpress.org/changeset/2605368
- https://wpscan.com/vulnerability/7cb39087-fbab-463d-9592-003e3fca6d34
- https://www.fortiguard.com/zeroday/FG-VD-21-052
- https://plugins.trac.wordpress.org/changeset/2605368
- https://wpscan.com/vulnerability/7cb39087-fbab-463d-9592-003e3fca6d34
- https://www.fortiguard.com/zeroday/FG-VD-21-052
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-24833",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "YOP Poll",
"versions": [
{
"status": "affected",
"version": "6.3.1",
"lessThan": "6.3.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-11-17T11:15:08.103",
"references": [
{
"url": "https://plugins.trac.wordpress.org/changeset/2605368",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/7cb39087-fbab-463d-9592-003e3fca6d34",
"tags": [
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://www.fortiguard.com/zeroday/FG-VD-21-052",
"tags": [
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/2605368",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wpscan.com/vulnerability/7cb39087-fbab-463d-9592-003e3fca6d34",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.fortiguard.com/zeroday/FG-VD-21-052",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of question and answer text parameters in Create Poll module."
},
{
"lang": "es",
"value": "El plugin YOP Poll de WordPress versiones anteriores a 6.3.1, está afectado por una vulnerabilidad de tipo Cross-Site Scripting almacenada, que es presentado en el módulo de vista previa de administración, donde un usuario con un rol tan bajo como el de autor puede ejecutar código de script arbitrario dentro del contexto de la aplicación. Esta vulnerabilidad es debido a una comprobación insuficiente de los parámetros de texto de las preguntas y respuestas en el módulo Create Poll"
}
],
"lastModified": "2026-06-17T03:40:59.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:yop-poll:yop_poll:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "87834720-D115-4676-B2CD-E2DE6B7EE8DF",
"versionEndExcluding": "6.3.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}