The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
History

Fri, 23 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wptablebuilder
Wptablebuilder wp Table Builder
CPEs cpe:2.3:a:wptablebuilder:wp_table_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Wptablebuilder
Wptablebuilder wp Table Builder
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Aug 2024 06:15:00 +0000

Type Values Removed Values Added
Description The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Title WP Table Builder <= 1.5.0 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-08-23T06:00:02.699Z

Updated: 2024-08-23T14:14:30.597Z

Reserved: 2024-04-03T19:44:40.109Z

Link: CVE-2024-3282

cve-icon Vulnrichment

Updated: 2024-08-23T14:14:22.217Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-23T06:15:03.827

Modified: 2024-08-23T16:18:28.547

Link: CVE-2024-3282

cve-icon Redhat

No data.