Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
YellowPencil vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Visual CSS Style Editor plugin <= 7.6.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YellowPencil YellowPencil Visual CSS Style Editor yellow-pencil-visual-theme-customizer allows Reflected XSS.This issue affects YellowPencil Visual CSS Style Editor: from n/a through <= 7.6.4.

CWE-79Oct 6, 2024
CVSS7.1v3.1EPSS0.302%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

yellowpencil visual_css_style_editor Cross-Site Request Forgery (CSRF)

The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows yp_option_update CSRF, as demonstrated by use of yp_remote_get to obtain admin access.

CWE-352May 13, 20191 related artifact
CVSS8.8v3.0EPSS1.89%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX