Vulnerability Details CVE-2021-24237
The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.633
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2021-24237
-
cpe:2.3:a:purethemes:findeo:-
-
cpe:2.3:a:purethemes:findeo:1.0.7
-
cpe:2.3:a:purethemes:findeo:1.0.7.2
-
cpe:2.3:a:purethemes:findeo:1.0.7.3
-
cpe:2.3:a:purethemes:findeo:1.1.0
-
cpe:2.3:a:purethemes:findeo:1.2.0
-
cpe:2.3:a:purethemes:findeo:1.2.1
-
cpe:2.3:a:purethemes:findeo:1.2.2
-
cpe:2.3:a:purethemes:findeo:1.2.3
-
cpe:2.3:a:purethemes:findeo:1.2.4
-
cpe:2.3:a:purethemes:findeo:1.2.6
-
cpe:2.3:a:purethemes:realteo:-