5.4

CVE-2023-2964

Exploit

Simple Iframe < 1.2.0 - Contributor+ Stored XSS

Simple Iframe <= 1.1.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via block attributes

The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.
Mögliche Gegenmaßnahme
Simple Iframe: Update to version 1.2.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Simple Iframe ProjectSimple Iframe SwPlatformwordpress Version < 1.2.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Simple Iframe
Version *-1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/97aac334-5323-41bb-90f0-d180bcc9162f
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/810faad2-b63d-497c-af00-b57a07705608
Third Party Advisory