Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wv7j-rf68-5jcq

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.8

Описание

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.

EPSS

Процентиль: 7%
0.00173
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
18 дней назад

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before rendering it on the public-facing form, allowing high-privilege users (such as administrators, who do not hold the unfiltered_html capability on multisite) to store JavaScript that executes in the browser of any visitor who views the form.

EPSS

Процентиль: 7%
0.00173
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79