CVE-2011-5181
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 10.43% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- clickdesk/clickdesk live support-live chat plugin
- Source
- cve@mitre.org
References
- http://osvdb.org/77338Exploit
- http://wordpress.org/extend/plugins/clickdesk-live-support-chat-plugin/changelog/
- http://www.securityfocus.com/archive/1/520624/100/0/threaded
- http://www.securityfocus.com/bid/50778Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71469
- http://osvdb.org/77338Exploit
- http://wordpress.org/extend/plugins/clickdesk-live-support-chat-plugin/changelog/
- http://www.securityfocus.com/archive/1/520624/100/0/threaded
- http://www.securityfocus.com/bid/50778Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71469
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.