Description
The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 15 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dachande663
Dachande663 hl Twitter |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:dachande663:hl_twitter:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Dachande663
Dachande663 hl Twitter |
Thu, 07 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-07T15:28:28.657Z
Reserved: 2024-04-10T19:09:28.559Z
Link: CVE-2024-3630
Updated: 2024-08-01T20:19:59.934Z
Status : Analyzed
Published: 2024-05-15T06:15:12.883
Modified: 2025-05-15T14:13:56.197
Link: CVE-2024-3630
No data.
OpenCVE Enrichment
No data.
Weaknesses