Логотип exploitDog
bind:CVE-2025-10567
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-10567

Количество 2

Количество 2

nvd логотип

CVE-2025-10567

3 месяца назад

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-8jg3-f28x-33h3

3 месяца назад

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-10567

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-8jg3-f28x-33h3

The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.

CVSS3: 6.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу