Inspiro Pro < 7.2.3 - Contributor+ Stored Cross-Site Scripting
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.
Affected products
Unknown · Inspiro PRO