Lucene search

K

Sitekit Security Vulnerabilities

cve
cve

CVE-2023-27628

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Webvitaly Sitekit plugin <= 1.3 versions.

6.5CVSS

5.2AI Score

0.0004EPSS

2023-09-27 03:18 PM
11
cve
cve

CVE-2023-5071

The Sitekit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sitekit_iframe' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

6.4CVSS

5AI Score

0.001EPSS

2023-10-20 07:15 AM
12