Lucene search

K
wpvulndbWpvulndbWPVDB-ID:B5CBB924-739E-4759-98B6-37166E904A0A
HistorySep 07, 2023 - 12:00 a.m.

Media Library Categories < 2.0.1 - Admin+ Stored XSS

2023-09-0700:00:00
wpscan.com
4
plugin
stored
xss
vulnerability
settings
admin
multisite

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Description The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CPENameOperatorVersion
wp-media-library-categorieseq2.0.1

5.4 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:B5CBB924-739E-4759-98B6-37166E904A0A