Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-05040
HistoryFeb 16, 2022 - 12:00 a.m.

WordPress Complianz plugin cross-site scripting vulnerability

2022-02-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
wordpress
complianz plugin
cross-site scripting
vulnerability
php
mysql
attackers

EPSS

0.001

Percentile

31.8%

WordPress is a set of blogging platforms developed using the PHP language by the WordPress (Wordpress) Foundation. The platform supports setting up personal blog sites on servers with PHP and MySQL. cross-site scripting vulnerability exists in versions prior to WordPress Complianz plugin 6.0.0, which stems from the plugin’s failure to filter and escape the s parameter before outputting it to the properties of the admin page, which can be exploited by attackers to cause reflected cross-site scripting.

EPSS

0.001

Percentile

31.8%