Lucene search

K
wpexploitWpvulndbWPEX-ID:E4BA26B4-5F4F-4C9E-AA37-885B30EF8088
HistoryJun 11, 2024 - 12:00 a.m.

Sitetweet <= 0.2 - Stored XSS via CSRF

2024-06-1100:00:00
wpvulndb
5
sitetweet 0.2 csrf june 25 2024 exploit update stored xss

5.9 Medium

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Description The plugin does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

The PoC will be displayed on June 25, 2024, to give users the time to update.

5.9 Medium

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Related for WPEX-ID:E4BA26B4-5F4F-4C9E-AA37-885B30EF8088