🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: WordPress

Mô tả

The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

Chi tiết

Trạng tháiDeferred
Điểm CVSS6.8 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Ngày công bố13:17 27/09/2026
Ngày cập nhật23:38 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-79

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
23:47 28/09/2026 CREATED cve MEDIUM

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).