Record summary

CVE-2016-10976 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMSafe Editor Plugin < 1.2 - CSS/JS-injectionCVSS 6.1

The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.

Impact

Unauthenticated attackers can inject malicious JavaScript or CSS code into the site, potentially stealing credentials, manipulating site content, or targeting site visitors.

Remediation

Update to the latest version of safe-editor plugin or apply the patch provided by the vendor.

WeaknessesCWE-79
AuthorsSplint3r7
Template tagscvecve2016wordpresswpwp-pluginxsssafe_editorvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:kodebyraaet:safe_editor:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3