Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvf5-2cph-6chj

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

EPSS

Процентиль: 3%
0.00133
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
5 дней назад

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before outputting them in the WordPress admin list-table columns, allowing users with contributor-level access or above to store a payload that executes as JavaScript in the session of higher-privileged users who view the affected post-list screen.

EPSS

Процентиль: 3%
0.00133
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79