CVE-2023-2757

🟡 Monitoruj

Obejście uwierzytelnienia w wtyczce Waiting dla WordPressa umożliwia atak XSS.

CVSS
7.4
EPSS
0.0%
Exploit
none
Vendor
plugin
Opis źródłowy (NVD)

The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to access functions to save plugin data that can potentially lead to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.4
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.0%
Opublikowano (NVD)2023-05-18 03:15:11 UTC
Ostatnia modyfikacja (NVD)2026-04-08 18:18:05 UTC
Referencje