← volver
CVE-2023-0375

Easy Affiliate Links < 3.7.1 - Contributor+ Stored XSS

CVSS 6.8 MEDIUMEPSS 0.7%
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.8EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
21 feb 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H