vendor:
Advanced Custom Fields
by:
Loading Kura Kura
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Advanced Custom Fields
Affected Version From: 5.7.2007
Affected Version To: 5.7.2007
Patch Exists: NO
Related CWE:
CPE: a:advanced_custom_fields:advanced_custom_fields:5.7.7
Platforms Tested: Windows, Linux
2018
WordPress Plugins Advanced-custom-fields 5.7.7 – Cross-Site Scripting
A Stored Cross-site scripting (XSS) was discovered in wordpress plugins easy testimonials 3.2. Three parameters(_ikcf_client _ikcf_position _ikcf_other) have Cross-Site Scripting.
Mitigation:
Update to the latest version of the plugin.