### [CVE-2021-24443](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24443) ![](https://img.shields.io/static/v1?label=Product&message=Youzify%20%E2%80%93%20BuddyPress%20Community%2C%20User%20Profile%2C%20Social%20Network%20%26%20Membership%20Plugin%20for%20WordPress&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.0.7%3C%201.0.7%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen) ### Description The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile. This could allow a low privilege user to gain unauthorised access to the admin side of the blog by targeting an admin, inducing them to view their profile with a malicious payload adding a rogue account for example. ### POC #### Reference - https://wpscan.com/vulnerability/a4432acd-df49-4a4f-8184-b55cdd5d4d34 #### Github - https://github.com/PT2OO/CVE-Collection - https://github.com/phutr4n/CVE-Collection