Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v663-v876-4rw6

Опубликовано: 12 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

EPSS

Процентиль: 65%
0.00495
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.

EPSS

Процентиль: 65%
0.00495
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79