Vulnerability Details CVE-2021-24214
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.041
EPSS Ranking 88.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-24214
-
cpe:2.3:a:daggerhartlab:openid_connect_generic_client:3.8.0
-
cpe:2.3:a:daggerhartlab:openid_connect_generic_client:3.8.1