Re: [FD] Give 2.3.0 - Reflected XSS (WordPress Plugin)

2019-03-22 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Feb 05, 2019 at 04:26:55PM +0100, Tim Coen wrote: > https://security-consulting.icu/blog/2019/02/wordpress-give-xss/ MITRE assigned CVE-2019-9909 for this vulnerability. - -- Henri Salo -BEGIN PGP SIGNATURE-

[FD] Give 2.3.0 - Reflected XSS (WordPress Plugin)

2019-02-05 Thread Tim Coen
* Vulnerability: XSS * Affected Software: [Give](https://wordpress.org/plugins/give/) * Affected Version: 2.3.0 * Patched Version: 2.3.1 * CVE: not requested * Risk: Medium * Vendor Contacted: 11/24/2018 * Vendor Fix: 12/13/2018 * Public Disclosure: 02/05/2019 * Credit: Tim