Описание
The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.43 (исключая)
cpe:2.3:a:metaphorcreations:ditty:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 57%
0.00347
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.7
github
больше 1 года назад
The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
EPSS
Процентиль: 57%
0.00347
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-79