Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpf6-j6mv-p249

Опубликовано: 27 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

EPSS

Процентиль: 30%
0.00109
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.

EPSS

Процентиль: 30%
0.00109
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79