Lucene search

K
wpvulndbWpvulndbWPVDB-ID:A38D3039-BACE-47BD-B40B-F57635BC920D
HistoryJan 05, 2024 - 12:00 a.m.

Easy Video Player < 1.2.2.11 - Contributor+ Stored XSS

2024-01-0500:00:00
wpscan.com
8
easy video player
stored xss
contributor role

AI Score

6.1

Confidence

High

EPSS

0

Percentile

14.0%

Description The plugin does not validate and escape the ratio_code attribute of its evp_embed_video shortcode before outputting it back in a page where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

AI Score

6.1

Confidence

High

EPSS

0

Percentile

14.0%

Related for WPVDB-ID:A38D3039-BACE-47BD-B40B-F57635BC920D