Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the admin screen.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 26 Nov 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the admin screen. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-11-26T04:33:51.381Z
Updated: 2024-11-26T14:09:26.088Z
Reserved: 2024-11-20T00:41:03.536Z
Link: CVE-2024-53278
Vulnrichment
Updated: 2024-11-26T14:04:19.589Z
NVD
Status : Received
Published: 2024-11-26T05:15:10.563
Modified: 2024-11-26T05:15:10.563
Link: CVE-2024-53278
Redhat
No data.