ZeroHour

CVE-2017-17096

CVSS 3.0
6.1 medium
EPSS
<1%p58
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in the Content Cards plugin before 0.9.7 for WordPress allows remote attackers to inject arbitrary JavaScript via crafted OpenGraph data.

Vendors
content cards project
Products
content cards
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.