Showing 2 vulnerabilities on this page for underConstruction

Signals CISA KEV Ransomware Nuclei
Noah Kagan vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress underConstruction plugin <= 1.21 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a through 1.21.

CWE-79Mar 31, 2024
CVSS5.9v3.1EPSS0.339%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

underConstruction <= 1.18 - Reflected Cross-Site Scripting

The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CWE-79Sep 1, 20211 related artifact
CVSS6.1v3.1EPSS2.32%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX