A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.14 is able to address this issue. The patch is identified as 1274afc635170daafd38306487b6bb8a01f78ecd. It is recommended to upgrade the affected component. VDB-248954 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/wp-plugins/pluscaptcha/commit/1274afc635170daafd38306487b6bb8a01f78ecd | Patch |
https://vuldb.com/?ctiid.248954 | Third Party Advisory |
https://vuldb.com/?id.248954 | Third Party Advisory |
Configurations
History
05 Jan 2024, 15:06
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:bestwebsoft:pluscaptcha:*:*:*:*:*:wordpress:*:* | |
References | () https://vuldb.com/?id.248954 - Third Party Advisory | |
References | () https://github.com/wp-plugins/pluscaptcha/commit/1274afc635170daafd38306487b6bb8a01f78ecd - Patch | |
References | () https://vuldb.com/?ctiid.248954 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
26 Dec 2023, 20:34
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-26 17:15
Updated : 2024-05-17 01:03
NVD link : CVE-2015-10127
Mitre link : CVE-2015-10127
CVE.ORG link : CVE-2015-10127
JSON object : View
Products Affected
bestwebsoft
- pluscaptcha
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')