Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-09988
HistoryFeb 10, 2022 - 12:00 a.m.

WordPress Visual CSS Style Editor plugin cross-site scripting vulnerability

2022-02-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
wordpress
css style editor
cross-site scripting
php
vulnerability
javascript
client-side.

EPSS

0.001

Percentile

31.7%

WordPress is a set of blogging platforms developed by the WordPress Foundation using the PHP language. WordPress Visual CSS Style Editor plugin in versions prior to 7.5.4 has a cross-site scripting vulnerability that stems from not cleaning up and escaping the wyp_page_type parameter. An attacker could use this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

31.7%