Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-24545 — WordPress Plugin HTML Author Bio description XSS | Kitploit
Tools/GitHubGitHub/dnr6419/cve-2021-24545
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & Education
GitHubdnr6419/cve-2021-24545

CVE-2021-24545

WordPress Plugin HTML Author Bio description XSS

View Repository
74 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-24545

This is an XSS vulnerability discovered in a plugin that is no longer distributed as a plugin.
WordPress Plugin HTML Author Bio description XSS

This vulnerability is caused by improper validation of the description parameter in /wp-admin/profile.php.
A remote attacker can exploit this by sending a maliciously crafted HTTP request.

Installation and Execution Order

1. WordPress Installation

When installing, please configure port forwarding in the docker-compose.yml file.

 $ docker-compose up  

2. WordPress initial & Plugin installation

Navigate to http://[web-server ip]:port/.
Proceed with the basic installation.
Install the plugin using the WP-HTML-Author-Bio-master.zip file.

3. PoC

Go to the following path:

http://[web-server ip]:port/wp-admin/profile.php

Insert an XSS payload using an img tag into the Biographical Info field.

image

Then, when you go to the WordPress blog, you can see the XSS executed as shown in the image below.

image

Precautions

You will not be held legally responsible for illegal exploitation of the above vulnerability.

If you illegally exploit the above vulnerabilities, you will not be held liable.

You must update the Docker version to the latest.

Source

https://wpscan.com/vulnerability/64267134-9d8c-4e0c-b24f-d18692a5775e

Download Tool