ZeroHour

CVE-2023-3746

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p34
Published
()
Modified
Description

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

Vendors
automattic
Products
activitypub
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.