Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-335g-mg6r-4m22

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

EPSS

Процентиль: 98%
0.54267
Средний

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)

EPSS

Процентиль: 98%
0.54267
Средний

Дефекты

CWE-79