6.1
CVSSv3

CVE-2020-29304

Published: 14/12/2020 Updated: 15/12/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import workflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

directoriespro directories pro

Exploits

WordPress DirectoriesPro plugin version 1345 suffers from multiple cross site scripting vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Self-reflected XSS in WordPress DirectoriesPro 1345 plugin disclosure <!--X-Subject-Header-End--> <!--X-Head-of-Mes ...