nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10976 CVE-2016-10976
MEDIUMNuclei
Safe Editor Plugin < 1.2 - CSS/JS-injection
Record summary
CVE-2016-10976 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSafe Editor Plugin < 1.2 - CSS/JS-injectionCVSS 6.1
The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS.
Impact
Unauthenticated attackers can inject malicious JavaScript or CSS code into the site, potentially stealing credentials, manipulating site content, or targeting site visitors.
Remediation
Update to the latest version of safe-editor plugin or apply the patch provided by the vendor.
WeaknessesCWE-79
AuthorsSplint3r7
Template tagscvecve2016wordpresswpwp-pluginxsssafe_editorvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:kodebyraaet:safe_editor:*:*:*:*:*:wordpress:*:*
https://wordpress.org/plugins/safe-editor/#developers https://github.com/ARPSyndicate/cvemon https://nvd.nist.gov/vuln/detail/CVE-2016-10976
Source: ProjectDiscovery
References
3wordpress.org
https://wordpress.org/plugins/safe-editor wpvulndb.com
https://wpvulndb.com/vulnerabilities/8497