Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rxh2-ghcp-6j9j

Опубликовано: 30 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

EPSS

Процентиль: 23%
0.00078
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.9
nvd
около 1 года назад

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

EPSS

Процентиль: 23%
0.00078
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-79