Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-66920
HistoryAug 18, 2021 - 12:00 a.m.

WordPress Plugin Cross-Site Scripting Vulnerability (CNVD-2021-66920)

2021-08-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
wordpress
plugin
cross-site scripting
php
mysql
vulnerability

EPSS

0.001

Percentile

24.8%

WordPress is the Wordpress Foundation’s set of blogging platform developed using the PHP language. The WordPress Plugin is a WordPress open source application plugin that supports personal blogging sites on PHP and MySQL servers. Manager fails to clean up or escape its “php_id” setting before exporting it back to the properties on the page, leading to a stored cross-site scripting issue. No details of the vulnerability are currently available.

EPSS

0.001

Percentile

24.8%