PatchSiren

Anyvar Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Anyvar Project CVE published 2017-03-02

CVE-2017-6103

CVE-2017-6103 describes a persistent cross-site scripting (XSS) vulnerability in the AnyVar WordPress plugin version 0.1.1. NVD classifies it as CWE-79 with a CVSS v3.0 score of 6.1 (medium), indicating network-based exploitation that requires user interaction and can affect confidentiality and integrity through script execution in a victim’s browser. The record was published by NVD on 2017-03-02 and late [truncated]