Описание
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.73 (исключая)Версия до 1.22.16 (исключая)
Одно из
cpe:2.3:a:pickplugins:post_grid:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:pickplugins:team_showcase:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 80%
0.01319
Низкий
7.5 High
CVSS3
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to import layouts including JavaScript supplied via a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
EPSS
Процентиль: 80%
0.01319
Низкий
7.5 High
CVSS3
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-79