Lucene search

K
wpvulndbWpvulndbWPVDB-ID:36A8D01B-5D13-4E51-A0E5-9D1F84BEAB78
HistoryNov 03, 2023 - 12:00 a.m.

Shortcode Menu <= 3.2 - Contributor+ Stored Cross-Site Scripting

2023-11-0300:00:00
wpscan.com
2
stored cross-site scripting
contributor
user input
escape output
web scripts

AI Score

5.5

Confidence

High

EPSS

0

Percentile

14.0%

Description The plugin does not properly sanitize user input or escape output in the ‘shortmenu’ shortcode, leading to a Stored Cross-Site Scripting vulnerability. This issue allows authenticated users with contributor-level and above permissions to inject arbitrary web scripts into pages.

AI Score

5.5

Confidence

High

EPSS

0

Percentile

14.0%

Related for WPVDB-ID:36A8D01B-5D13-4E51-A0E5-9D1F84BEAB78