Lucene search

K
wpvulndbWpvulndbWPVDB-ID:2D93720B-2733-4947-95E8-9D390806AF03
HistoryOct 25, 2023 - 12:00 a.m.

Delete Me < 3.1 - Contributor+ Stored Cross-Site Scripting via Shortcode

2023-10-2500:00:00
wpscan.com
2
plugin
stored cross-site scripting
shortcode
contributor
validation
escape
attributes

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Description The plugin does not validate and escape some of its attributes for the plugin_delete_me shortcode before outputting them back into the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.

CPENameOperatorVersion
eq3.1

6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:2D93720B-2733-4947-95E8-9D390806AF03