2 results (0.006 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in a comment on an Instagram post. Una vulnerabilidad de Cross-Site Scripting (XSS) en el plugin Web-Dorado Instagram Feed WD en versiones anteriores a la 1.3.1 Premium para WordPress permite que los atacantes remotos inyecten scripts web o HTML arbitrarios pasando cargas útiles en un comentario en una publicación de Instagram. WordPress WD Instagram Feed version 1.3.0 suffers from multiple cross site scripting vulnerabilities. • https://medium.com/%40squeal/wd-instagram-feed-1-3-0-xss-vulnerabilities-cve-2018-10300-and-cve-2018-10301-7173ffc4c271 https://wpvulndb.com/vulnerabilities/9393 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an Instagram profile's bio. Una vulnerabilidad de Cross-Site Scripting (XSS) en el plugin Web-Dorado Instagram Feed WD en versiones anteriores a la 1.3.1 para WordPress permite que los atacantes remotos inyecten scripts web o HTML arbitrarios pasando cargas útiles en una biografía de perfil de Instagram. WordPress WD Instagram Feed version 1.3.0 suffers from multiple cross site scripting vulnerabilities. • https://medium.com/%40squeal/wd-instagram-feed-1-3-0-xss-vulnerabilities-cve-2018-10300-and-cve-2018-10301-7173ffc4c271 https://wpvulndb.com/vulnerabilities/9393 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •