Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp58-32qm-mgjw

Опубликовано: 09 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

EPSS

Процентиль: 12%
0.00041
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
nvd
около 1 месяца назад

The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.

EPSS

Процентиль: 12%
0.00041
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79