🔐 CVE Alert

CVE-2021-47984

MEDIUM 6.4

WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
9th

WordPress Plugin WP24 Domain Check 1.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the fieldnameDomain parameter. Attackers can inject JavaScript payloads through the plugin settings form at options.php that execute in the browsers of administrators viewing the settings page.

CWE CWE-79
Vendor wp24
Product wp24 domain check
Published Jun 8, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for wp24 wp24 domain check

Be the first to know when new medium vulnerabilities affecting wp24 wp24 domain check are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

WP24 / WP24 Domain Check
1.6.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/49377 wordpress.org: https://wordpress.org/plugins/wp24-domain-check/ vulncheck.com: https://www.vulncheck.com/advisories/wordpress-plugin-wp24-domain-check-stored-xss

Credits

Mehmet Kelepçe / Gais Cyber Security