Lucene search

K
patchstackAsif Nawaz MinhasPATCHSTACK:2EB9773368F7FE0D0D35342552377114
HistorySep 15, 2021 - 12:00 a.m.

WordPress YITH Maintenance Mode plugin <= 1.3.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

2021-09-1500:00:00
Asif Nawaz Minhas
patchstack.com
10

0.001 Low

EPSS

Percentile

19.6%

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Asif Nawaz Minhas (Patchstack Red Team) in WordPress YITH Maintenance Mode plugin (versions <= 1.3.7). Vulnerable parameter: &yith_maintenance_newsletter_submit_label.

Solution

           Update the WordPress YITH Maintenance Mode plugin to the latest available version (at least 1.3.8).
CPENameOperatorVersion
yith maintenance modele1.3.7

0.001 Low

EPSS

Percentile

19.6%

Related for PATCHSTACK:2EB9773368F7FE0D0D35342552377114