6.4
CVE-2023-4838
- EPSS 0.08%
- Published 09.09.2023 02:15:46
- Last modified 21.11.2024 08:36:04
- Source security@wordfence.com
- CVE-Watchlists
- Open
Simple Download Counter <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'before' and 'after'. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Mögliche Gegenmaßnahme
Simple Download Counter: Update to version 1.6.1, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Product
Simple Download Counter
Version
1.6
Data is provided by the National Vulnerability Database (NVD)
Plugin-planet ≫ Simple Download Counter SwPlatformwordpress Version <= 1.6
| Type | Source | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.25 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| security@wordfence.com | 6.4 | 3.1 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
|