Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B1A25E70-9C96-4EA6-BD41-B271606D4D50
HistorySep 27, 2023 - 12:00 a.m.

Sitekit < 1.4 - Contributor+ Stored XSS

2023-09-2700:00:00
wpscan.com
3
sitekit
contributor
xss
vulnerability
stored cross-site scripting
attacks
software

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Description The plugin does not validate and escape some parameters, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CPENameOperatorVersion
eq1.4

6.1 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:B1A25E70-9C96-4EA6-BD41-B271606D4D50