CVE-2021-47984
WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS
CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
9th
WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the fieldnameDomain parameter. Attackers can inject JavaScript payloads through the plugin settings form at options.php that execute in the browsers of administrators viewing the settings page.
| CWE | CWE-79 |
| Vendor | wp24 |
| Product | wp24 domain check |
| Published | Jun 8, 2026 |
| Last Updated | Jun 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for wp24 wp24 domain check
Be the first to know when new medium vulnerabilities affecting wp24 wp24 domain check are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
WP24 / WP24 Domain Check
1.6.2
References
Credits
Mehmet Kelepçe / Gais Cyber Security