Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2chv-vxpq-wr23

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.

EPSS

Процентиль: 39%
0.00174
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
почти 6 лет назад

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.

EPSS

Процентиль: 39%
0.00174
Низкий