Lucene search

K
wpexploitMikaWPEX-ID:A4162E96-A3C5-4F38-A60B-AA3ED9508985
HistoryFeb 09, 2022 - 12:00 a.m.

E2Pdf < 1.16.45 - Admin+ Stored Cross-Site Scripting (XSS)

2022-02-0900:00:00
Mika
93

0.001 Low

EPSS

Percentile

35.9%

The plugin does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Refer to https://mikadmin.fr/tech/XSS-Stored-E2Pdf-798ef69b0e13c36acf5446358d57c965Dx90666bNvCw98.pdf

0.001 Low

EPSS

Percentile

35.9%

Related for WPEX-ID:A4162E96-A3C5-4F38-A60B-AA3ED9508985