Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99627
HistoryNov 10, 2021 - 12:00 a.m.

WordPress Storefront Footer Text plugin cross-site scripting vulnerability

2021-11-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
wordpress
storefront
footer text
plugin
cross-site scripting
vulnerability
php
javascript code
client side

EPSS

0.001

Percentile

24.8%

WordPress is the Wordpress Foundation’s set of blogging platforms developed using the PHP language. WordPress Storefront Footer Text plugin in version 1.0.1 and earlier has a cross-site scripting vulnerability, which stems from the lack of ““Footer Credit Text”” on the plugin page for user-supplied data and output data checksum filtering. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

24.8%