Description
The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-15986 | The Community by PeepSo WordPress plugin before 6.3.1.2 does not sanitise and escape various parameters and generated URLs before outputting them back attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |
References
History
Wed, 13 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-22T17:35:43.770Z
Reserved: 2024-01-01T17:24:12.282Z
Link: CVE-2024-0187
Updated: 2024-08-01T17:41:16.122Z
Status : Modified
Published: 2024-01-16T16:15:14.233
Modified: 2025-05-22T18:15:32.253
Link: CVE-2024-0187
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD