WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Unauthenticated Stored Cross-Site Scripting
40Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 1.2%
de la publicación al arma
Publicada en NVD7 mar
VulnCheck14 feb
probabilidad de explotación
1.2%top 36% de las CVE
explotación observada
síVulnCheck
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.
Productos afectados
Unknown · WP Cerber Security, Anti-spam & Malware Scan