Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qgr-qvc8-p8wf

Опубликовано: 28 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.

WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.

EPSS

Процентиль: 6%
0.00162
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
22 дня назад

WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.

EPSS

Процентиль: 6%
0.00162
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79