Описание
The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.26.2 (исключая)
cpe:2.3:a:wp-dreams:ajax_search:*:*:*:*:pro:wordpress:*:*
EPSS
Процентиль: 35%
0.00146
Низкий
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
CVSS3: 6.1
github
почти 3 года назад
The Ajax Search Pro WordPress plugin before 4.26.2 does not sanitise and escape various parameters before outputting them back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
EPSS
Процентиль: 35%
0.00146
Низкий
6.1 Medium
CVSS3