The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-06-07T06:00:03.057Z
Updated: 2024-08-01T20:55:10.444Z
Reserved: 2024-05-16T13:16:12.075Z
Link: CVE-2024-5003
Vulnrichment
Updated: 2024-08-01T20:55:10.444Z
NVD
Status : Analyzed
Published: 2024-06-07T06:15:12.000
Modified: 2024-07-18T16:18:33.020
Link: CVE-2024-5003
Redhat
No data.