Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c62f-23hx-w7cg

Опубликовано: 18 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

EPSS

Процентиль: 15%
0.00235
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
nvd
5 дней назад

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.

EPSS

Процентиль: 15%
0.00235
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79