Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j8j2-69r7-q88p

Опубликовано: 01 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

EPSS

Процентиль: 94%
0.14426
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission

EPSS

Процентиль: 94%
0.14426
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79