Логотип exploitDog
bind:CVE-2020-11509
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11509

Количество 2

Количество 2

nvd логотип

CVE-2020-11509

почти 6 лет назад

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-mr39-vf45-2r7q

больше 3 лет назад

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-11509

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).

CVSS3: 6.1
2%
Низкий
почти 6 лет назад
github логотип
GHSA-mr39-vf45-2r7q

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу