logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-0937

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-0937

Description:
The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Last updated date:
03/23/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/23/2023
Reference url to background

https://wpscan.com/vulnerability/5110ff02-c721-43eb-b13e-50aca25e1162

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy