Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-103358
HistoryDec 28, 2021 - 12:00 a.m.

WordPress Buttonizer-Smart Floating Action Button plugin cross-site scripting vulnerability

2021-12-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
wordpress
buttonizer
smart floating action button
cross-site scripting
vulnerability
data validation
javascript code

EPSS

0.001

Percentile

24.8%

WordPress is a set of blogging platforms developed by the Wordpress Foundation using the PHP language. The platform supports setting up personal blog sites on PHP and MySQL servers. buttonizer-Smart Floating Action Button plugin has a cross-site scripting vulnerability in versions prior to 2.5.5, which stems from a lack of data validation filtering of user-supplied data and output. An attacker could exploit the vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

24.8%