Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvr9-h38m-rc5q

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-79