Описание
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
EPSS
Процентиль: 15%
0.00235
Низкий
6.8 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.8
github
2 дня назад
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views the affected page.
EPSS
Процентиль: 15%
0.00235
Низкий
6.8 Medium
CVSS3
Дефекты
CWE-79