Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-70735
HistorySep 08, 2021 - 12:00 a.m.

WordPress Cross-Site Scripting Vulnerability (CNVD-2021-70735)

2021-09-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
5

0.001 Low

EPSS

Percentile

37.5%

WordPress is a set of blogging platforms developed by the WordPress (Wordpress) Foundation using the PHP language. A cross-site scripting vulnerability exists in the WordPress plugin, which stems from a cross-site scripting (XSS) vulnerability in the settings page of the SMS Alert Order Notifications plugin in version 3.4.7 and prior versions. An attacker could exploit this vulnerability to obtain sensitive information.

CPENameOperatorVersion
wordpress sms alertle3.4.7

0.001 Low

EPSS

Percentile

37.5%