Ad Injection <= 1.2.0.19 - Authenticated (Admin+) Stored Cross-Site Scripting
mediumThe Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is...
- CVSS:
- 5.5
- Affected:
- up to 1.2.0.19
- Fix:
- No patched version reported
- Disclosed:
- Mar 22, 2022