The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Arnesonium
Arnesonium openpgp Form Encryption |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:arnesonium:openpgp_form_encryption:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Arnesonium
Arnesonium openpgp Form Encryption |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-13T06:00:05.011Z
Updated: 2024-08-01T20:26:56.962Z
Reserved: 2024-04-17T14:31:54.538Z
Link: CVE-2024-3919

Updated: 2024-08-01T20:26:56.962Z

Status : Analyzed
Published: 2024-07-13T06:15:02.900
Modified: 2025-05-13T13:57:06.830
Link: CVE-2024-3919

No data.