6.4 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
31 packages
- fedigroups
- sway-assign-cgroups
- haskellPackages.groups
- haskellPackages.semigroups
- haskellPackages.groups-generic
- haskellPackages.finite-semigroups
- haskellPackages.quickcheck-groups
- haskellPackages.numbered-semigroups
- python312Packages.dependency-groups
- python313Packages.dependency-groups
- python314Packages.dependency-groups
- gnomeExtensions.kolour-groups-windows
- haskellPackages.gogol-groups-settings
- haskellPackages.commutative-semigroups
- haskellPackages.gogol-groups-migration
- haskellPackages.amazonka-resourcegroups
- chickenPackages_5.chickenEggs.posix-groups
- python312Packages.mypy-boto3-resource-groups
- python313Packages.mypy-boto3-resource-groups
- python314Packages.mypy-boto3-resource-groups
- python312Packages.azure-mgmt-managementgroups
- python313Packages.azure-mgmt-managementgroups
- python314Packages.azure-mgmt-managementgroups
- haskellPackages.amazonka-resourcegroupstagging
- python312Packages.types-aiobotocore-resource-groups
- python313Packages.types-aiobotocore-resource-groups
- python312Packages.mypy-boto3-resourcegroupstaggingapi
- python313Packages.mypy-boto3-resourcegroupstaggingapi
- python314Packages.mypy-boto3-resourcegroupstaggingapi
- python312Packages.types-aiobotocore-resourcegroupstaggingapi
- python313Packages.types-aiobotocore-resourcegroupstaggingapi
- @LeSuisse dismissed
Groups <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'groups_group_info' Shortcode
The Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'groups_group_info' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
References
Affected products
- =<3.10.0
Ignored packages (31)
pkgs.fedigroups
Approximation of groups usable with Fediverse software that implements the Mastodon client API
pkgs.sway-assign-cgroups
Place GUI applications into systemd scopes for systemd-oomd compatibility
pkgs.haskellPackages.groups
Groups
pkgs.haskellPackages.semigroups
Anything that associates
pkgs.haskellPackages.groups-generic
Generically derive Group instances
pkgs.haskellPackages.finite-semigroups
Operations and classification for finite semigroups
pkgs.haskellPackages.quickcheck-groups
Testing group class instances with QuickCheck
pkgs.haskellPackages.numbered-semigroups
A sequence of semigroups, for composing stuff in multiple spatial directions
pkgs.python312Packages.dependency-groups
A standalone implementation of PEP 735 Dependency Groups
pkgs.python313Packages.dependency-groups
A standalone implementation of PEP 735 Dependency Groups
pkgs.python314Packages.dependency-groups
A standalone implementation of PEP 735 Dependency Groups
pkgs.gnomeExtensions.kolour-groups-windows
Window management with color groups and grayscale effects
pkgs.haskellPackages.gogol-groups-settings
Google Groups Settings SDK
pkgs.haskellPackages.commutative-semigroups
Commutative semigroups
pkgs.haskellPackages.gogol-groups-migration
Google Groups Migration SDK
pkgs.haskellPackages.amazonka-resourcegroups
Amazon Resource Groups SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-25.11 2.0-unstable-2025-04-16
- nixos-25.11-small 2.0-unstable-2025-04-16
- nixpkgs-25.11-darwin 2.0-unstable-2025-04-16
pkgs.chickenPackages_5.chickenEggs.posix-groups
Access POSIX group information
pkgs.python312Packages.mypy-boto3-resource-groups
Type annotations for boto3 resource-groups
-
nixos-25.11 boto3-resource-groups-1.41.0
- nixos-25.11-small boto3-resource-groups-1.41.0
- nixpkgs-25.11-darwin boto3-resource-groups-1.41.0
pkgs.python313Packages.mypy-boto3-resource-groups
Type annotations for boto3 resource-groups
-
nixos-unstable boto3-resource-groups-1.42.3
- nixpkgs-unstable boto3-resource-groups-1.42.3
- nixos-unstable-small boto3-resource-groups-1.42.3
-
nixos-25.11 boto3-resource-groups-1.41.0
- nixos-25.11-small boto3-resource-groups-1.41.0
- nixpkgs-25.11-darwin boto3-resource-groups-1.41.0
pkgs.python314Packages.mypy-boto3-resource-groups
Type annotations for boto3 resource-groups
-
nixos-unstable boto3-resource-groups-1.42.3
- nixpkgs-unstable boto3-resource-groups-1.42.3
- nixos-unstable-small boto3-resource-groups-1.42.3
pkgs.python312Packages.azure-mgmt-managementgroups
This is the Microsoft Azure Management Groups Client Library
pkgs.python313Packages.azure-mgmt-managementgroups
This is the Microsoft Azure Management Groups Client Library
pkgs.python314Packages.azure-mgmt-managementgroups
This is the Microsoft Azure Management Groups Client Library
pkgs.haskellPackages.amazonka-resourcegroupstagging
Amazon Resource Groups Tagging API SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-25.11 2.0-unstable-2025-04-16
- nixos-25.11-small 2.0-unstable-2025-04-16
- nixpkgs-25.11-darwin 2.0-unstable-2025-04-16
pkgs.python312Packages.types-aiobotocore-resource-groups
Type annotations for aiobotocore resource-groups
pkgs.python313Packages.types-aiobotocore-resource-groups
Type annotations for aiobotocore resource-groups
pkgs.python312Packages.mypy-boto3-resourcegroupstaggingapi
Type annotations for boto3 resourcegroupstaggingapi
-
nixos-25.11 boto3-resourcegroupstaggingapi-1.41.0
- nixos-25.11-small boto3-resourcegroupstaggingapi-1.41.0
- nixpkgs-25.11-darwin boto3-resourcegroupstaggingapi-1.41.0
pkgs.python313Packages.mypy-boto3-resourcegroupstaggingapi
Type annotations for boto3 resourcegroupstaggingapi
-
nixos-unstable boto3-resourcegroupstaggingapi-1.42.3
- nixpkgs-unstable boto3-resourcegroupstaggingapi-1.42.3
- nixos-unstable-small boto3-resourcegroupstaggingapi-1.42.3
-
nixos-25.11 boto3-resourcegroupstaggingapi-1.41.0
- nixos-25.11-small boto3-resourcegroupstaggingapi-1.41.0
- nixpkgs-25.11-darwin boto3-resourcegroupstaggingapi-1.41.0
pkgs.python314Packages.mypy-boto3-resourcegroupstaggingapi
Type annotations for boto3 resourcegroupstaggingapi
-
nixos-unstable boto3-resourcegroupstaggingapi-1.42.3
- nixpkgs-unstable boto3-resourcegroupstaggingapi-1.42.3
- nixos-unstable-small boto3-resourcegroupstaggingapi-1.42.3
pkgs.python312Packages.types-aiobotocore-resourcegroupstaggingapi
Type annotations for aiobotocore resourcegroupstaggingapi