Anyfont <= 2.2.3 - Cross-Site Scripting
highCross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the text parameter.
- CVSS:
- 7.2
- Affected:
- up to 2.2.3
- Fix:
- No patched version reported
- Disclosed:
- Jul 2, 2014