Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19815
HistoryFeb 10, 2022 - 12:00 a.m.

WordPress Asset CleanUp: Page Speed Booster plugin cross-site scripting vulnerability

2022-02-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
wordpress
asset cleanup
page speed booster
cross-site scripting
vulnerability
php
data validation
javascript
exploit

EPSS

0.001

Percentile

41.8%

WordPress is a blogging platform developed by the WordPress Foundation using the PHP language.Asset CleanUp:Page Speed Booster WordPress plugin in versions prior to 1.3.8.5 has a cross-site scripting vulnerability that stems from a lack of data validation filtering of user-supplied data and output. The vulnerability can be exploited by attackers to execute JavaScript code on the client side.

EPSS

0.001

Percentile

41.8%