Lucene search

K
wpvulndbWpvulndbWPVDB-ID:D5B95156-EDA4-4BD4-BD56-81672F345700
HistoryAug 16, 2023 - 12:00 a.m.

User Submitted Posts < 20230811 - Unauthenticated Stored XSS

2023-08-1600:00:00
wpscan.com
2
plugin
sanitize
escape
user-submitted-content
unauthenticated
stored xss
attacks

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.6%

Description The plugin does not sanitize and escape the user-submitted-content parameter, which could allow unauthenticated users to perform Stored XSS attacks

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

22.6%

Related for WPVDB-ID:D5B95156-EDA4-4BD4-BD56-81672F345700