Lucene search

K
wpvulndbWpvulndbWPVDB-ID:1280284D-80F2-4660-8D6F-741BEC416EAC
HistoryFeb 02, 2024 - 12:00 a.m.

Easy Digital Downloads < 3.2.7 - Shop Manager+ Stored XSS

2024-02-0200:00:00
wpscan.com
7
vulnerability
stored cross-site scripting
input sanitization
output escaping
authenticated attackers
shop manager-level access
arbitrary web scripts
web security

AI Score

5.8

Confidence

High

EPSS

0

Percentile

14.0%

Description The plugin is vulnerable to Stored Cross-Site Scripting via the variable pricing option title due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop manger-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AI Score

5.8

Confidence

High

EPSS

0

Percentile

14.0%

Related for WPVDB-ID:1280284D-80F2-4660-8D6F-741BEC416EAC