Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-62175
HistoryJul 19, 2022 - 12:00 a.m.

WordPress plugin CDI cross-site scripting vulnerability

2022-07-1900:00:00
China National Vulnerability Database
www.cnvd.org.cn
18
wordpress
plugin
cdi
cross-site scripting
vulnerability
php
ajax
attackers

EPSS

0.001

Percentile

36.8%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. WordPress plugin is an application plugin. versions prior to WordPress plugin CDI 5.1.9 contain a cross-site scripting vulnerability that stems from the plugin’s failure to clean up and escape parameters before outputting them back to the response of an AJAX operation, which could be exploited by attackers to perform cross-site scripting attacks. exploit this vulnerability to perform cross-site scripting attacks.

EPSS

0.001

Percentile

36.8%