CVE-2021-24878 describes a Reflected Cross-Site Scripting (XSS) vulnerability in the SupportCandy WordPress plugin versions prior to 2.2.7. This flaw occurs because the plugin fails to properly sanitize and escape query string parameters before displaying them on pages containing the [wpsc_create_ticket] shortcode. With a CVSS score of 6.1 (Medium), this vulnerability can be exploited remotely with low attack complexity, requiring user interaction to achieve partial confidentiality and integrity impacts. The FAUCET Risk Score is 81/100, indicating a notable risk. Currently, there is no evidence of active exploitation, and no Metasploit or ExploitDB modules are available. While Nuclei templates exist for detection, community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.7CPE matchmatch criteria | cpe:2.3:a:supportcandy:supportcandy:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.