PT-2024-10565 · Thimo Grauerholz · Wp-Spreadplugin
Thimo Grauerholz
·
Published
2024-04-21
·
Updated
2024-06-04
·
CVE-2015-10132
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Thimo Grauerholz WP-Spreadplugin versions up to 3.8.6.1
Description
A problematic vulnerability was found in Thimo Grauerholz WP-Spreadplugin on WordPress, affecting unknown code of the file spreadplugin.php. The manipulation of the
Spreadplugin argument leads to cross-site scripting. The attack can be initiated remotely.Recommendations
Upgrade to version 3.8.6.6 to address this issue. As a temporary workaround, consider restricting access to the
spreadplugin.php file until the upgrade is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp-Spreadplugin