vendor:
WordPress Pool
by:
Unknown
4.3
CVSS
MEDIUM
Cross-site scripting (XSS)
79
CWE
Product Name: WordPress Pool
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-Unknown
CPE: a:wordpress:pool
Platforms Tested:
Unknown
Cross-site scripting vulnerability in WordPress Pool
The WordPress Pool application fails to properly sanitize user-supplied input, leading to a cross-site scripting vulnerability. An attacker can exploit this vulnerability to execute arbitrary script code in the context of the affected site, potentially stealing authentication credentials and launching further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user-supplied input before using it in any context.