Логотип exploitDog
bind:CVE-2024-2640
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2640

Количество 2

Количество 2

nvd логотип

CVE-2024-2640

больше 1 года назад

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-c7x7-vc85-8vmc

больше 1 года назад

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-2640

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-c7x7-vc85-8vmc

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу