CVE-2021-33851 describes a medium-severity cross-site scripting (XSS) vulnerability affecting the "Customize Login Image" plugin for WordPress, specifically versions prior to 3.5.3. An authenticated attacker can inject malicious JavaScript into the "Custom logo link" field, which executes when a user accesses the plugin's settings page. This allows for client-side arbitrary code execution, potentially leading to information disclosure or unauthorized actions within the user's browser session. While not listed in CISA's KEV catalog and lacking public exploit code on Metasploit or ExploitDB, Nuclei templates exist, and there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.4CPE matchmatch criteria | cpe:2.3:a:apasionados:customize_login_image:3.4:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.