Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fp6q-wmwj-3m9p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed

EPSS

Процентиль: 38%
0.00162
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed

EPSS

Процентиль: 38%
0.00162
Низкий

Дефекты

CWE-79