OpenID Connect Generic Client 3.8.0-3.8.1 - Reflected Cross-Site Scripting
2021-04-07 00:00
Austin BentleyStrategic Overview
StatusPatched in 3.8.2
Affected PluginOpenID Connect Generic Client
Affected Version
3.8.0 – < 3.8.2CVSS6.1Medium
CVE
CVE-2021-24214Vulnerability Overview
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
Technical Analysis
REMEDIATION: Update to version 3.8.2, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C