WordPress Securimage-WP 3.2.4 - Cross-Site Scripting
WordPress Securimage-WP 3.2.4 plugin contains a cross-site scripting vulnerability via siwp_test.php. An attacker can execute arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
securimage-wpPoC 已收录
CVSS7.2