Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56554
HistoryJun 30, 2022 - 12:00 a.m.

WordPress Login using WordPress Users plugin跨站脚本漏洞

2022-06-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
17

0.001 Low

EPSS

Percentile

25.0%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. WordPress plugin is an application plugin. cross-site scripting vulnerability exists in versions prior to WordPress Login using WordPress Users plugin 1.13.4, which stems from the plugin not cleaning and escaping some of its settings. An attacker with high privileges, such as an administrator, can use this vulnerability to execute JavaScript code on the client side.

0.001 Low

EPSS

Percentile

25.0%