Lucene search

K
osvGoogleOSV:GHSA-35MH-F6P8-PJ2C
HistoryMay 14, 2022 - 3:49 a.m.

WPGlobus plugin Stored XSS & CSRF security vulnerability

2022-05-1403:49:04
Google
osv.dev
5
wpglobus plugin
stored xss
csrf
wordpress
wp-admin/options.php

AI Score

6

Confidence

High

EPSS

0.001

Percentile

26.0%

The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.

AI Score

6

Confidence

High

EPSS

0.001

Percentile

26.0%

Related for OSV:GHSA-35MH-F6P8-PJ2C