LiveActive security incident?Get immediate response
CVE Record

CVE-2021-4252: WP-Ban ban-options.php toggle_checkbox cross site scripting

A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76. It is recommended to apply a patch to fix this issue. The identifier VDB-216209 was assigned to this vulnerability.

LowCVSS 3.5Not KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

CVE-2021-4252 is a low-severity cross-site scripting issue in WP-Ban. A remotely supplied browser user-agent value could be handled unsafely in the ban options area, potentially letting an authenticated attacker influence what another user sees.

Executive priority

Handle in normal vulnerability management cadence unless WP-Ban is deployed on sensitive or high-user-volume sites. Business risk is mainly admin-session abuse or content manipulation, not direct data theft or service outage based on available evidence.

Technical view

The source describes improper handling of $_SERVER["HTTP_USER_AGENT"] in ban-options.php, affecting the toggle_checkbox function. The assigned CVSS 3.1 score is 3.5, with low attack complexity, privileges required, and user interaction required. The named fix is commit 13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76.

Likely exposure

Exposure is limited to environments running WP-Ban. The source bundle does not identify affected version ranges, package distribution details, or confirmed vulnerable deployment conditions, so asset owners must verify installed plugin code against vendor history.

Exploitation context

The issue is remotely triggerable, but CVSS indicates privileges are required and user interaction is required. The CVE is not listed as KEV in the provided bundle, and no cited source here confirms active exploitation.

Researcher notes

Evidence is incomplete on affected versions. The CVE maps to CWE-707, while the described behavior is cross-site scripting through user-agent handling. Avoid assuming broader WordPress impact beyond WP-Ban without vendor confirmation.

Mitigation direction

  • Apply the vendor patch associated with commit 13e0b1e922f3aaa3f8fcb1dd6d50200dd693fd76.
  • Check WP-Ban vendor guidance for the fixed release or equivalent remediation.
  • Prioritize patching sites where untrusted users can authenticate.
  • Limit administrative access to WP-Ban settings until fixed.

Validation and detection

  • Inventory production sites for WP-Ban usage and installed version evidence.
  • Verify installed code includes the patch commit or equivalent output handling.
  • Review ban-options.php for unsafe display of user-agent-derived values.
  • Retest in staging with benign user-agent values and confirm encoded output.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-707: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-4252 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Low
CVSS
3.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
3.5CVSS 3.1LowCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N2.11.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

3.5Low
CVSS 3.1 vector shape for CVE-2021-4252Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
unspecifiedWP-Bann/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-707 · source CWE mapping

Improper Neutralization

Improper Neutralization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.