The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
History

Wed, 06 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wpulike
Wpulike wp Ulike
CPEs cpe:2.3:a:wpulike:wp_ulike:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpulike
Wpulike wp Ulike
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 Nov 2024 06:15:00 +0000

Type Values Removed Values Added
Description The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Title WP ULike < 4.7.5 - Admin+ Stored XSS via Widgets
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-11-06T06:00:05.843Z

Updated: 2024-11-06T15:51:51.920Z

Reserved: 2024-08-16T12:54:24.448Z

Link: CVE-2024-7879

cve-icon Vulnrichment

Updated: 2024-11-06T15:51:46.875Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-06T06:15:03.813

Modified: 2024-11-06T18:17:17.287

Link: CVE-2024-7879

cve-icon Redhat

No data.