Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-70770
HistoryMar 24, 2022 - 12:00 a.m.

WordPress Optimole plugin cross-site scripting vulnerability

2022-03-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
wordpress
optimole
cross-site scripting
vulnerability
image optimization
delayed loading
php
open source application
attackers
attacks
clean up
escape
setting

EPSS

0.001

Percentile

21.4%

WordPress is the Wordpress Foundation’s set of blogging platform developed using the PHP language. WordPress plugin is a WordPress open source application plugin. WordPress plugin Optimole version 3.3.2 has a cross-site scripting vulnerability that stems from the failure of image optimization and delayed loading to clean up and escape its The vulnerability is caused by the failure of Image Optimization and Delayed Loading to clean up and escape its “Delayed Loading Background Image for Selector” setting, which can be exploited by attackers to perform cross-site scripting attacks.

EPSS

0.001

Percentile

21.4%