Target First Plugin 2.0 - Unauthenticated Stored XSS via Licence Key
Vulnerability Description
The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stored XSS vulnerability. An attacker could change the licence key value through a POST on any URL with the 'weeWzKey' parameter that will be save as the 'weeID option and is not sanitized.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24305
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Vincent MICHEL
Affected Vendor
TargetFirst
View all reports →