Lucene search

K
patchstackAsif Nawaz Minhas (Patchstack Red Team)PATCHSTACK:2E2270D1399874E99D4C899324808FE7
HistoryAug 17, 2021 - 12:00 a.m.

WordPress Icegram plugin <= 2.0.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

2021-08-1700:00:00
Asif Nawaz Minhas (Patchstack Red Team)
patchstack.com
7

0.001 Low

EPSS

Percentile

19.4%

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Asif Nawaz Minhas in WordPress Icegram plugin (versions <= 2.0.2). Vulnerable at “Headline” (&message_data[16][headline]) input.

Solution

           Update the WordPress Icegram plugin to the latest available version (at least 2.0.3).
CPENameOperatorVersion
icegramle2.0.2

0.001 Low

EPSS

Percentile

19.4%

Related for PATCHSTACK:2E2270D1399874E99D4C899324808FE7