Описание
The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.1.5 (исключая)
cpe:2.3:a:getshortcodes:shortcodes_ultimate:*:*:*:*:pro:wordpress:*:*
EPSS
Процентиль: 33%
0.00134
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.7
github
больше 1 года назад
The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, making it possible for attackers with a Contributor account to conduct Stored XSS attacks.
EPSS
Процентиль: 33%
0.00134
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-79