Логотип exploitDog
bind:CVE-2021-24637
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-24637

Количество 2

Количество 2

nvd логотип

CVE-2021-24637

больше 4 лет назад

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x8c7-9c7c-54qw

больше 3 лет назад

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-24637

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-x8c7-9c7c-54qw

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу