Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9hj-4382-6wh4

Опубликовано: 15 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

EPSS

Процентиль: 83%
0.01944
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 2 лет назад

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

EPSS

Процентиль: 83%
0.01944
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79