Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-388v-6f9f-263v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

EPSS

Процентиль: 46%
0.00236
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is executed in the victim's browser.

EPSS

Процентиль: 46%
0.00236
Низкий