Lucene search

K
wpvulndbRyanWPVDB-ID:4EEE26BD-A27E-4509-A3A5-8019DD48E429
HistoryApr 29, 2020 - 12:00 a.m.

WordPress < 5.4.1 - Authenticated Cross-Site Scripting (XSS) in Customizer

2020-04-2900:00:00
Ryan
wpscan.com
33

EPSS

0.002

Percentile

51.5%

Authenticated users could corrupt JSON data in the Customizer of other users’ to inject malicious JavaScript.

EPSS

0.002

Percentile

51.5%

Related for WPVDB-ID:4EEE26BD-A27E-4509-A3A5-8019DD48E429