Lucene search

K
wpvulndbRyanWPVDB-ID:E721D8B9-A38F-44AC-8520-B4A9ED6A5157
HistoryApr 29, 2020 - 12:00 a.m.

WordPress < 5.4.1 - Cross-Site Scripting (XSS) in wp-object-cache

2020-04-2900:00:00
Ryan
wpscan.com
42

EPSS

0.006

Percentile

79.2%

WordPress’ Object Cache that caches data from the database did not validate or encode the cache key. If an attacker managed to inject a malicious cache key that was then output in a third party plugin, it could lead to XSS.

EPSS

0.006

Percentile

79.2%

Related for WPVDB-ID:E721D8B9-A38F-44AC-8520-B4A9ED6A5157