Multiple XSS Issues in WP-Editor Plugin for WordPress
CVE-2016-10877
6.1MEDIUM
Summary
The WP-Editor plugin prior to version 1.2.6.3 for WordPress has multiple vulnerabilities related to Cross-Site Scripting (XSS). These issues can be exploited by attackers to inject malicious scripts that execute in the context of an administrator's session. This vulnerability poses a risk to the security of WordPress sites using the plugin, potentially leading to unauthorized actions and data exposure. Users are encouraged to update to the latest version to mitigate these security concerns.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved