VendorsGistPress Projectgistpressall versions
Vulnerabilities

GistPress Project GistPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2020-8498
XSS exists in the shortcode functionality of the GistPress plugin before 3.0.2 for WordPress via the includes/class-gistpress.php id parameter. This allows an attacker with the WordPress Contributor role to execute arbitrary JavaScript code with the privileges of other users (e.g., ones who have the publish_posts capability).
Published 2020-01-30 · Modified
5.4EPSS 0.012