Lucene search

K
wpvulndbWpvulndbWPVDB-ID:6561723D-3987-4A52-8549-D563D69D1457
HistoryMar 08, 2023 - 12:00 a.m.

W4 Post List < 2.4.5 - Contributor+ Stored XSS

2023-03-0800:00:00
wpscan.com
4
vulnerability
stored xss
w4 post list
contributor
software

EPSS

0.001

Percentile

17.7%

The plugin does not sanitise and escape the w4pl[no_items_text] parameter, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

EPSS

0.001

Percentile

17.7%

Related for WPVDB-ID:6561723D-3987-4A52-8549-D563D69D1457