Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fq48-ww4g-mgh4

Опубликовано: 14 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

EPSS

Процентиль: 25%
0.00084
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows changing the plugin settings, including required user levels for specific features. This could also lead to Stored Cross-Site Scripting due to the lack of escaping in some of the settings

EPSS

Процентиль: 25%
0.00084
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352