PT-2019-7459 · WordPress+1 · The Exquisite Ultimate Newspaper Theme+1

Publicado

2019-10-22

·

Atualizado

2019-10-24

·

CVE-2015-9500

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions The Exquisite Ultimate Newspaper theme version 1.3.3 for WordPress
Description The issue is related to a Cross-Site Scripting (XSS) vulnerability. It occurs via the anchor identifier to the assets/js/jquery.foundation.plugins.js file. This allows for potential malicious script execution.
Recommendations For The Exquisite Ultimate Newspaper theme version 1.3.3, consider disabling access to the assets/js/jquery.foundation.plugins.js file until a patch is available. Restrict the use of the anchor identifier to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-9500

Produtos afetados

The Exquisite Ultimate Newspaper Theme
Jquery