Smart Custom 404 Error Page <= 11.4.7 - Reflected Cross-Site Scripting
mediumThe Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUEST_URI'] in all versions up to, and including, 11.4.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- CVSS:
- 6.1
- Affected:
- up to 11.4.7
- Fixed in:
- 11.4.8
- Disclosed:
- Oct 3, 2024