About Author Box < 1.0.2 - Cross-Site Scripting
mediumThe About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before outputting them in attributes, which could allow user with a role as low as contributor to perform Cross-Site Scripting attacks.
- CVSS:
- 6.4
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Oct 26, 2021