Beveiligingsadvies

CVE-2024-6668

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-15 20:07:08
Laatst bijgewerkt 2025-05-20 19:24:18
Toegewezen door WPScan
CVSS-score 5.4
Status PUBLISHED

Beschrijving

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks