CVE-2019-19133
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input.
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- csshero/csshero
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/155558/WordPress-CSS-Hero-4.0.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9966Third Party Advisory
- http://packetstormsecurity.com/files/155558/WordPress-CSS-Hero-4.0.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Dec/6Exploit, Mailing List, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9966Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.