Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mp4f-p2f3-644f

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

EPSS

Процентиль: 32%
0.00123
Низкий

Дефекты

CWE-352