Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4r8x-26vf-3hx6

Опубликовано: 22 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

EPSS

Процентиль: 38%
0.00161
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

EPSS

Процентиль: 38%
0.00161
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79