Gwyn's Imagemap Selector <= 0.3.3 - Reflected Cross-Site Scripting
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 2.1%
from disclosure to weapon
Published on NVDMay 23
VulnCheck+1112d
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
yesVulnCheck
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.
Affected products
Unknown · Gwyn's Imagemap Selector