Lucene search

K
wpvulndbWpvulndbWPVDB-ID:9452A34F-8E66-41B2-B5F1-0A8550E34EB5
HistoryNov 15, 2023 - 12:00 a.m.

Responsive Column Widgets <= 1.2.7 - Reflected XSS

2023-11-1500:00:00
wpscan.com
4
responsive column widgets
reflected cross-site scripting
high privilege users
admin
security vulnerability

AI Score

8.1

Confidence

High

EPSS

0.001

Percentile

17.0%

Description The plugin does not sanitise and escape the tab parameter before outputting it back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

AI Score

8.1

Confidence

High

EPSS

0.001

Percentile

17.0%

Related for WPVDB-ID:9452A34F-8E66-41B2-B5F1-0A8550E34EB5