CVE-2016-10973: Brafton

Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.

The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter to BraftonAdminPage.php.

Affected products

  • Brafton Brafton: before 3.4.8 (fixed in 3.4.8)

Published 2019-09-16. Last modified 2026-06-17.