CVE-2021-24176: WordPress JH 404 Logger <=1.1 - Cross-Site Scripting

2025-08-01 WordPress JH 404 Logger PoC Public

Description

WordPress JH 404 Logger plugin through 1.1 contains a cross-site scripting vulnerability. Referer and path of 404 pages are not properly sanitized when they are output in the WordPress dashboard, which can lead to executing arbitrary JavaScript code.

PoC

id: CVE-2021-24176

info:
  name: WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
  author: Ganofins
  severity: medium
  description: WordPress JH 404 Logger plugin through 1.1 contains a cross-site scripting vulnerability. Referer and path of 404 pages are not properly sanitized when they are output in the WordPress dashboard, which can lead to executing arbitrary JavaScript code.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.
  remediation: |
    Update to the latest version of WordPress JH 404 Logger plugin (>=1.2) which addresses the XSS vulnerability.
  reference:
    - https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585
    - https://wordpress.org/plugins/jh-404-logger/
    - https://ganofins.com/blog/my-first-cve-2021-24176/
    - https://nvd.nist.gov/vuln/detail/CVE-2021-24176
    - https://github.com/ARPSyndicate/cvemon
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    cvss-score: 5.4
    cve-id: CVE-2021-24176
    cwe-id: CWE-79
    epss-score: 0.02044
    epss-percentile: 0.80204
    cpe: cpe:2.3:a:jh_404_logger_project:jh_404_logger:*:*:*:*:*:wordpress:*:*
  metadata:
    max-request: 1
    vendor: jh_404_logger_project
    product: jh_404_logger
    framework: wordpress
  tags: cve2021,cve,wordpress,wp-plugin,xss,wpscan,jh_404_logger_project,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/plugins/jh-404-logger/readme.txt"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "JH 404 Logger"

      - type: status
        status:
          - 200
# digest: 490a004630440220295e58935344bbcce35720a87388c4693bb9ca89afefacd5a1b5247483310f3c0220180e9d2abe6a9c42b97d7dd1b2cc20d17a21cf181cba7258f0dd8fce77f598fe:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities