Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-21743
HistoryDec 18, 2021 - 12:00 a.m.

WordPress Lets-Box Plugin Cross-Site Scripting Vulnerability

2021-12-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
wordpress
lets-box plugin
cross-site scripting
vulnerability
client side
javascript code

EPSS

0.001

Percentile

36.2%

WordPress is a set of blogging platforms developed by the Wordpress Foundation using the PHP language.Lets-Box Plugin is a WordPress open source application plugin.Wordpress Lets-Box Plugin has a cross-site scripting vulnerability in versions prior to 1.15.3, which stems from the Lets-Box Plugin’s search function lacks user-supplied data and output data validation filtering. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

36.2%