Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56556
HistoryJun 30, 2022 - 12:00 a.m.

WordPress Malware Scanner plugin跨站脚本漏洞

2022-06-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
wordpress
malware scanner plugin
cross-site scripting
vulnerability
client side

EPSS

0.001

Percentile

24.8%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. WordPress plugin is an application plugin. WordPress Malware Scanner plugin versions prior to 4.5.2 have a cross-site scripting vulnerability that stems from the plugin not cleaning up and escaping some of its settings, which could be exploited by a highly privileged attacker such as an administrator to execute JavaScript code on the client side. The vulnerability can be exploited to execute JavaScript code on the client side.

EPSS

0.001

Percentile

24.8%