Lucene search

K
wpvulndbWpvulndbWPVDB-ID:FC9CB6DE-BCC1-419A-81BD-BE3DE6018471
HistoryNov 17, 2023 - 12:00 a.m.

Login Screen Manager <= 3.5.2 - Stored XSS via CSRF

2023-11-1700:00:00
wpscan.com
2
login screen manager
csrf
vulnerability
xss
admin
software
attack

AI Score

6

Confidence

High

EPSS

0.001

Percentile

24.1%

Description The plugin does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

AI Score

6

Confidence

High

EPSS

0.001

Percentile

24.1%

Related for WPVDB-ID:FC9CB6DE-BCC1-419A-81BD-BE3DE6018471