🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: WordPress

Mô tả

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Chi tiết

Trạng tháiDeferred
Điểm CVSS7.2 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Ngày công bố11:16 21/12/2025
Ngày cập nhật17:10 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-79

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
17:17 28/09/2026 CREATED cve HIGH

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).