Medium severity6.1NVD Advisory· Published May 6, 2021· Updated Jun 17, 2026
CVE-2021-24214
CVE-2021-24214
Description
The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:daggerhartlab:openid_connect_generic_client:3.8.0:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:daggerhartlab:openid_connect_generic_client:3.8.0:*:*:*:*:wordpress:*:*
- cpe:2.3:a:daggerhartlab:openid_connect_generic_client:3.8.1:*:*:*:*:wordpress:*:*
- daggerhart/OpenID Connect Generic Clientv5Range: 3.8.0
- Range: 3.8.0, 3.8.1
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/31cf0dfb-4025-4898-a5f4-fc7115565a10nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.