VulnerabilityModified
CVE-2023-0442
The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a…
MEDIUM 6.1EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
The Loan Comparison WordPress plugin before 1.5.3 does not validate and escape some of its query parameters before outputting them back in a page/post via an embedded shortcode, which could allow an attacker to inject javascript into into the site via a crafted URL.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.49% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- loan comparison project/loan comparison
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/34d95d88-4114-4597-b4db-e9f5ef80d322Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/34d95d88-4114-4597-b4db-e9f5ef80d322Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.