Описание
The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.6.4 (исключая)
cpe:2.3:a:wedevs:dokan:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 49%
0.00255
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
около 2 лет назад
The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
EPSS
Процентиль: 49%
0.00255
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79