Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5j5-mxj7-f5fg

Опубликовано: 07 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

EPSS

Процентиль: 44%
0.00217
Низкий

3.8 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.8
nvd
почти 2 года назад

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

EPSS

Процентиль: 44%
0.00217
Низкий

3.8 Low

CVSS3

Дефекты

CWE-79