Lucene search

K
nvd[email protected]NVD:CVE-2024-0420
HistoryFeb 12, 2024 - 4:15 p.m.

CVE-2024-0420

2024-02-1216:15:08
web.nvd.nist.gov
2
mappress
plugin
xss
wordpress
admin
dashboard
stored
attacks
permission

AI Score

5.7

Confidence

High

EPSS

0

Percentile

9.0%

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing Contributors and above roles to perform Stored Cross-Site Scripting attacks

AI Score

5.7

Confidence

High

EPSS

0

Percentile

9.0%