Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-39071

Опубликовано: 28 авг. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.

EPSS

Процентиль: 6%
0.00162
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
22 дня назад

WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.

EPSS

Процентиль: 6%
0.00162
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79