5.4
CVE-2023-2964
- EPSS 0.13%
- Veröffentlicht 10.07.2023 16:15:51
- Zuletzt bearbeitet 23.04.2025 17:16:32
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Simple Iframe <= 1.1.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via block attributes
The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.
Mögliche Gegenmaßnahme
Simple Iframe: Update to version 1.2.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Simple Iframe
Version
*-1.1.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Simple Iframe Project ≫ Simple Iframe SwPlatformwordpress Version < 1.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.323 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|