VulnerabilityModified
CVE-2020-15535
Persistent XSS can occur via any of the registration fields.
MEDIUM 6.1EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- bestsoftinc/car rental system
- Source
- cve@mitre.org
References
- https://packetstormsecurity.com/files/157118/WordPress-Car-Rental-System-1.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10172Third Party Advisory
- https://packetstormsecurity.com/files/157118/WordPress-Car-Rental-System-1.3-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10172Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.