Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j9qp-w82r-g5cf

Опубликовано: 30 нояб. 2021
Источник: github
Github: Не прошло ревью

Описание

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before saving the plugin's setting. As a result, any logged-in user on a vulnerable site could update the settings and store rogue JavaScript on each of its posts and pages.

EPSS

Процентиль: 40%
0.0018
Низкий

Дефекты

CWE-79