Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79hx-hhr4-x2xv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

EPSS

Процентиль: 81%
0.01572
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 4 лет назад

The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.

EPSS

Процентиль: 81%
0.01572
Низкий

Дефекты

CWE-79