ZeroHour

CVE-2016-0765

PoC ×2
CVSS 3.0
6.1 medium
EPSS
2%p78
Published
()
Modified
Description

Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.

Vendors
elfden
Products
eshop plugin
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.