Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mg7h-r8f5-67xj

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data parameter of the pp_get_forms_by_builder_type AJAX action before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

EPSS

Процентиль: 44%
0.00216
Низкий

Дефекты

CWE-79