Описание
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.
Ссылки
- http://packetstormsecurity.com/files/162623/WordPress-Stop-Spammers-2021.8-Cross-Site-Scripting.htmlExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- http://packetstormsecurity.com/files/162623/WordPress-Stop-Spammers-2021.8-Cross-Site-Scripting.htmlExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2021.9 (исключая)
cpe:2.3:a:trumani:stop_spammers:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 95%
0.17943
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
github
больше 3 лет назад
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.
EPSS
Процентиль: 95%
0.17943
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79