WordPress WPify Woo Czech <3.5.7 - Cross-Site Scripting
WordPress WPify Woo Czech plugin before 3.5.7 contains a cross-site scripting vulnerability. The plugin uses the Vies library 2.2.0, which has a sample file outputting $_SERVER['PHP_SELF'] in an attribute without being escaped first. The issue is only exploitable when the web server has the PDO driver installed and write access to the example directory.
wpify-woo-czechPoC 已收录
CVSS7.2