Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5g9-jf88-x4g8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

EPSS

Процентиль: 37%
0.00162
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 5 лет назад

An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.

EPSS

Процентиль: 37%
0.00162
Низкий

Дефекты

CWE-79