Noah Kagan Vulnerabilities and Affected Products
Vulnerabilities associated with underConstruction.
Products
Clear product- underConstruction2 vulnerabilities
- Scroll Triggered Box1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-30548MEDIUM | WordPress underConstruction plugin <= 1.21 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a through 1.21. CWE-79Mar 31, 2024 | CVSS5.9v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-39320MEDIUM | underConstruction <= 1.18 - Reflected Cross-Site ScriptingThe underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path. | CVSS6.1v3.1 | EPSS2.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |