Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21501
HistorySep 12, 2019 - 11:33 a.m.

Cross-site Scripting (XSS)

2019-09-1211:33:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.005

Percentile

77.7%

wordpress is vulnerable to cross-site scripting. The attack is due to lack of validation of parameters in the post previews by authenticated users which allows an attacker to inject and execute arbitrary scripts.