CVE-2021-47927
📛 CVE Title
(no title)
Description
WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps_admin_forum_add_name parameter, which are stored and executed when the forum is accessed.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 6.4 / 10
- CVSS vector
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N- Effective score
- 6.4 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2021-47927
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-10 13:16:28 UTC
- NVD last modified
- 2026-05-12 14:24:15 UTC
- NVD CVSS v3.1
- 6.4 / 10 MEDIUM source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N- Exploitability subscore
- 3.1 / 10
- Impact subscore
- 2.7 / 10
- EPSS score
- 0.0003 (probability of exploitation in next 30 days)
- EPSS percentile
- 10.24% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD-assigned CWE(s):
CWE-79
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-05-24 23:58 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2021-34789 - Assigner
- VulnCheck
- Published
- May 10, 2026, 12:43:48 PM
- Updated
- May 24, 2026, 1:37:08 AM
- EUVD base score (CVSS 4.0)
-
5.1 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N - EUVD-reported EPSS
- 0.0300
- Vendors
- Wpsymposiumpro
- Products
-
WP Symposium Pro (2021.10)
ENISA description: WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps_admin_forum_add_name parameter, which are stored and executed when the forum is accessed.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (7)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://www.wpsymposiumpro.com/ tenable:www.wpsymposiumpro.com
- https://nvd.nist.gov/vuln/detail/CVE-2021-47927 tenable:nvd.nist.gov
- https://wordpress.org/plugins/wp-symposium-pro/ tenable:wordpress.org
- https://www.cve.org/CVERecord?id=CVE-2021-47927 tenable:www.cve.org
- https://www.exploit-db.com/exploits/50514 tenable:www.exploit-db.com
- https://www.first.org/epss/ tenable:www.first.org
- https://www.vulncheck.com/advisories/wordpress-plugin-wp-symposium-pro-stored-xss-via-wps-admin-forum-add-name tenable:www.vulncheck.com
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- http://www.wpsymposiumpro.com/ disclosure@vulncheck.com
- https://wordpress.org/plugins/wp-symposium-pro/ disclosure@vulncheck.com
- https://www.exploit-db.com/exploits/50514 disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/wordpress-plugin-wp-symposium-pro-stored-xss-via-wps-admin-forum-add-name disclosure@vulncheck.com
Remediations (10)
-
web:cybersecuritynews.com
Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.
2026-05-26 03:07 UTC -
web:petri.com
How to Fix Issues Caused by Windows Cumulative Updates using Known Issue Rollback (Image Credit: Microsoft) KIR works at the code level.
2026-05-26 03:07 UTC -
web:support.microsoft.com
It includes updates from previous security and non-security releases, along with an additional fix . To learn more about differences between security updates, optional non-security preview updates, out-of-band (OOB) updates, and continuous innovation, see Windows monthly updates explained.
2026-05-26 03:07 UTC -
web:www.bleepingcomputer.com
Microsoft has released an out-of-band (OOB) update to fix a security vulnerabilities affecting Windows 11 Enterprise devices that receive hotpatch updates instead of the regular Patch Tuesday ...
2026-05-26 03:07 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-26 03:07 UTC -
web:www.digitaltrends.com
Microsoft has released another emergency Windows 11 update after a January patch triggered widespread app crashes, Outlook failures, and cloud sync issues, forcing the company into rare back to ...
2026-05-26 03:07 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-26 03:07 UTC -
web:www.windowscentral.com
Another out of band update has been issued to Windows 11 users to address a major bug that caused Outlook to become inoperable after January's disastrous Patch Tuesday updates.
2026-05-26 03:07 UTC -
web:www.xda-developers.com
Windows 11's second emergency patch of the month fixes a nasty Outlook issue You no longer need to deploy your own fixes A few days ago, we caught wind that Outlook was really struggling on ...
2026-05-26 03:07 UTC -
web:www.zdnet.com
Why you need Microsoft's new emergency Windows patch - and the black-screen bug to watch for While Microsoft has been fixing bugs caused by the Patch Tuesday update, another glitch has surfaced.
2026-05-26 03:07 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.