DirectoriesPro by SabaiApps <= 1.3.45 - Reflected Cross-Site Scripting
medium
A cross-site scripting (XSS) vulnerability exists in the SabaiApps WordPress Directories Pro plugin version 1.3.45 and previous, allows attackers who have convinced a site administrator to import a specially crafted CSV file to inject arbitrary web script or HTML as the victim is proceeding through the file import work...
- CVSS:
- 6.1
- Affected:
- up to 1.3.46
- Fixed in:
- 1.3.46
- Disclosed:
- Dec 11, 2020
CVE-2020-29304 on NVD →
DirectoriesPro Plugin by SabaiApps <= 1.3.45 - Cross-Site Scripting via _drts_form_build_id, _t_ Parameters
medium
A cross-site scripting (XSS) vulnerability in the SabaiApp Directories Pro plugin 1.3.45 for WordPress allows remote attackers to inject arbitrary web script or HTML via a POST to /wp-admin/admin.php?page=drts/directories&q=%2F with _drts_form_build_id parameter containing the XSS payload and _t_ parameter set to an in...
- CVSS:
- 6.1
- Affected:
- up to 1.3.46
- Fixed in:
- 1.3.46
- Disclosed:
- Dec 10, 2020
CVE-2020-29303 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database