Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf44-j366-mwxm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).

EPSS

Процентиль: 64%
0.00473
Низкий

Связанные уязвимости

CVSS3: 5.4
nvd
около 6 лет назад

XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).

EPSS

Процентиль: 64%
0.00473
Низкий