amtyThumb posts <= 8.2.0 - Cross-Site Scripting
mediumXSS exists in the amtyThumb amty-thumb-recent-post (aka amtyThumb posts or wp-thumb-post) plugin 8.1.3 for WordPress via the query string to amtyThumbPostsAdminPg.php. An attempt to patch this vulnerability was made with 8.2.0, however, it is still exploitable by users who are logged-in.
- CVSS:
- 5.4
- Affected:
- up to 8.2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 18, 2017