Lucene search

K
wpvulndbWpvulndbWPVDB-ID:5611D45A-4BA5-4EF1-B931-CDE06BD4F674
HistoryOct 02, 2023 - 12:00 a.m.

wordpress publish post email notification < 1.0.2.3 - Admin+ Stored XSS

2023-10-0200:00:00
wpscan.com
15
wordpress
plugin
version
admin
stored xss
email notification
validation
escape
parameters
admin role
unfiltered html
multisite setup

AI Score

6

Confidence

High

EPSS

0.001

Percentile

18.6%

Description The plugin does not validate and escape some parameters, which could allow users with the admin role and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

AI Score

6

Confidence

High

EPSS

0.001

Percentile

18.6%

Related for WPVDB-ID:5611D45A-4BA5-4EF1-B931-CDE06BD4F674