Описание
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.
Ссылки
- Product
- Exploit
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.8 (включая)
cpe:2.3:a:wpforms:wpforms:*:*:*:*:lite:wordpress:*:*
EPSS
Процентиль: 8%
0.00029
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
25 дней назад
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.
EPSS
Процентиль: 8%
0.00029
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79