CVE-2021-47927: WordPress Plugin WP Symposium Pro 2021.10 Stored XSS via wps_admin_forum_add_name
WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting insufficient sanitization of the forum name parameter. Attackers can submit POST requests to the admin setup page with JavaScript payloads in the wps_admin_forum_add_name parameter, which are stored and executed when the forum is accessed.
Security readout for executives and security teams
This is a stored cross-site scripting flaw in the WordPress WP Symposium Pro plugin. An authenticated attacker could save malicious script content in a forum name, causing it to run later when the forum is viewed. The available sources rate it medium severity and do not show confirmed active exploitation. Exposure appears limited to WordPress sites running WP Symposium Pro 2021.10, especially where authenticated users can reach the vulnerable forum setup functionality. The source bundle does not identify other affected versions or products. Prioritize this for WordPress environments using WP Symposium Pro. It is not a critical infrastructure emergency, but stored XSS can expose administrator sessions, alter site content, or support follow-on compromise if left unresolved. Mitigation focus: Inventory WordPress sites for WP Symposium Pro and confirm installed version.; Check vendor, WordPress.org, and VulnCheck guidance for fixed or supported versions.; Restrict access to forum setup and administrative plugin functions..
Prepared
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.