Lucene search

K
wpvulndbWpvulndbWPVDB-ID:4CB7FCA9-9222-4119-9780-4A63B1A2DC99
HistoryJan 20, 2024 - 12:00 a.m.

WP Recipe Maker < 9.1.1 - Contributor+ Stored Cross-Site Scripting via icon_color

2024-01-2000:00:00
wpscan.com
9
vulnerable
stored cross-site scripting
plugin
input sanitization
output escaping
authenticated attackers
contributor-level permissions

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

20.2%

Description The plugin is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘wprm-recipe-text-share’ shortcode in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

20.2%

Related for WPVDB-ID:4CB7FCA9-9222-4119-9780-4A63B1A2DC99