Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjm4-fjw9-x2fh

Опубликовано: 25 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

EPSS

Процентиль: 23%
0.00077
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 1 года назад

The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites hosted on WordPress.com.

EPSS

Процентиль: 23%
0.00077
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79