Beveiligingsadvies

CVE-2024-4483

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-07-29 06:00:01
Laatst bijgewerkt 2024-08-01 20:40:47
Toegewezen door WPScan
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting