Описание
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.8.176 (исключая)Версия до 1.8.176 (исключая)
Одно из
cpe:2.3:a:westguardsolutions:ws_form:*:*:*:*:lite:wordpress:*:*
cpe:2.3:a:westguardsolutions:ws_form:*:*:*:*:pro:wordpress:*:*
EPSS
Процентиль: 94%
0.14426
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 6.1
github
почти 4 года назад
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
EPSS
Процентиль: 94%
0.14426
Средний
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
CWE-79