terser (JS Package) < 5.14.2 - Denial of Service
lowThe package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.
- CVSS:
- 3.7
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.1
- Disclosed:
- Jul 14, 2022