Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24162

Опубликовано: 05 апр. 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:free:wordpress:*:*
Версия до 4.0.4 (исключая)
cpe:2.3:a:expresstech:responsive_menu:*:*:*:*:pro:wordpress:*:*
Версия до 4.0.4 (исключая)

EPSS

Процентиль: 32%
0.00123
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

github
больше 3 лет назад

In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to include malicious JavaScript, therefore allowing an attacker to inject payloads that could aid in further infection of the site.

EPSS

Процентиль: 32%
0.00123
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352