Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-33994

Опубликовано: 30 июл. 2022
Источник: nvd
CVSS3: 3
EPSS Низкий

Описание

The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gutenberg_project:gutenberg:*:*:*:*:*:wordpress:*:*
Версия до 13.7.3 (включая)

EPSS

Процентиль: 50%
0.00274
Низкий

3 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.

EPSS

Процентиль: 50%
0.00274
Низкий

3 Low

CVSS3

Дефекты

CWE-79