Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wvh-wcmq-7555

Опубликовано: 31 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

EPSS

Процентиль: 42%
0.00199
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

EPSS

Процентиль: 42%
0.00199
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79