Application Passwords <= 0.1.3 - Reflected Cross-Site Scripting via reject_url
mediumThe Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the...
- CVSS:
- 5.4
- Affected:
- up to 0.1.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 5, 2025