Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42c6-gcr4-xh6h

Опубликовано: 17 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.

EPSS

Процентиль: 26%
0.00092
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only SuperAdmins (in multisite) / admins (in single site) can create forms, however there is a settings allowing them to give lower roles access to such feature.

EPSS

Процентиль: 26%
0.00092
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79