Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-102401
HistoryDec 01, 2021 - 12:00 a.m.

WordPress Plugin Cross-Site Scripting Vulnerability (CNVD-2021-102401)

2021-12-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
wordpress
cross-site scripting
vulnerability
check & log email plugin
php
cnvd-2021-102401

EPSS

0.001

Percentile

43.6%

WordPress is the Wordpress Foundation’s set of blogging platform developed using the PHP language. The WordPress plugin is a WordPress open source application plugin. cross-site scripting vulnerability exists in versions of WordPress prior to Check & Log Email plugin 1.0.4. The vulnerability stems from the fact that the d parameter is not escaped before it is output back to the property. An attacker could exploit this vulnerability to conduct cross-site scripting attacks.

EPSS

0.001

Percentile

43.6%

Related for CNVD-2021-102401