Описание
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
Ссылки
- ExploitThird Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ProductThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.04 (исключая)
cpe:2.3:a:display-widgets_project:display-widgets:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 45%
0.00227
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
The display-widgets plugin before 2.04 for WordPress has XSS via the wp-admin/admin-ajax.php?action=dw_show_widget id_base, widget_number, or instance parameter.
EPSS
Процентиль: 45%
0.00227
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79