Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the admin screen.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 26 Nov 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing the admin screen. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-11-26T14:09:26.088Z
Reserved: 2024-11-20T00:41:03.536Z
Link: CVE-2024-53278

Updated: 2024-11-26T14:04:19.589Z

Status : Received
Published: 2024-11-26T05:15:10.563
Modified: 2024-11-26T05:15:10.563
Link: CVE-2024-53278

No data.