Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-6164
HistoryNov 22, 2023 - 4:15 p.m.

Input validation

2023-11-2216:15:00
PRIOn knowledge base
www.prio-n.com
7
mainwp
dashboard
wordpress
css
injection
administrator
access
vulnerable
nvd

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.2%

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.

CPENameOperatorVersion
mainwple4.5.1.2

7.1 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

14.2%

Related for PRION:CVE-2023-6164