CVSS Summary
| Score | 7.5 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | None |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Partial |
Last revised:
This plugin contains a reflected XSS vulnerability which can be used against admin users.
Current state: Fixed
| Score | 7.5 High |
|---|---|
| Vector | Network |
| Complexity | Low |
| Authentication | None |
| Confidentiality | Partial |
| Integrity | Partial |
| Availability | Partial |
Works in browsers that don’t attempt to block reflected XSS:
http://localhost/wp-admin/options-general.php?action=duplicate_post_save_as_new_post&post=%3Cscript%3Ealert%28123%29%3C/script%3E
Upgrade immediately.