Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-59810
HistoryMay 07, 2022 - 12:00 a.m.

WordPress Fast Flow plugin跨站脚本漏洞

2022-05-0700:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.001 Low

EPSS

Percentile

40.2%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. WordPress plugin is an application plugin. cross-site scripting vulnerability exists in versions of WordPress Fast Flow plugin prior to 1.2.12, which stems from the plugin’s failure to clean up and escape page parameters before outputting properties back to the admin dashboard. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

CPENameOperatorVersion
wordpress fast flow pluginlt1.2.12

0.001 Low

EPSS

Percentile

40.2%