Beveiligingsadvies

CVE-2024-6708

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-15 20:07:09
Laatst bijgewerkt 2025-05-20 19:23:48
Toegewezen door WPScan
CVSS-score 4.8
Status PUBLISHED

Beschrijving

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.