Lucene search

K
wpvulndbWpvulndbWPVDB-ID:F298F9CC-1EF1-415C-AA8D-D0E0E63461EC
HistoryJan 12, 2024 - 12:00 a.m.

Posts to Page <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

2024-01-1200:00:00
wpscan.com
3
wordpress
posts to page
plugin
cross-site scripting
authenticated
contributor
input sanitization

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Description The Posts to Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:F298F9CC-1EF1-415C-AA8D-D0E0E63461EC