ZeroHour

CVE-2023-0420

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p14
Published
()
Modified
Description

The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF

Vendors
custom post type and taxonomy gui manager project
Products
custom post type and taxonomy gui manager
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.