Lucene search

K
wpvulndbWpvulndbWPVDB-ID:7EAFE92F-B0AB-4417-834F-2C1920225347
HistoryDec 19, 2022 - 12:00 a.m.

Sidebar Widgets by CodeLights <= 1.4 - Admin+ Stored Cross Site Scripting

2022-12-1900:00:00
wpscan.com
6
plugin
stored cross site scripting
admin
high privileged users
administrator
web scripts
unfiltered html capability
multisite setups

0.0005 Low

EPSS

Percentile

17.9%

The plugin does not properly sanitize or escape the Extra CSS class parameter, allowing high privileged users, such as an administrator to inject arbitrary web scripts into pages, even when the unfiltered html capability is disabled (e.g in multisite setups.)

CPENameOperatorVersion
codelights-shortcodes-and-widgetseq*

0.0005 Low

EPSS

Percentile

17.9%

Related for WPVDB-ID:7EAFE92F-B0AB-4417-834F-2C1920225347