Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-4483
HistoryJul 29, 2024 - 6:00 a.m.

CVE-2024-4483 Email Encoder < 2.2.2 - Admin+ Stored XSS

2024-07-2906:00:01
WPScan
github.com
9
cve-2024-4483
email encoder
wordpress
stored xss
admin page

AI Score

5.7

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:jannisthuemmig:email_encoder:*:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "jannisthuemmig",
    "product": "email_encoder",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "2.2.2",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

5.7

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-4483