Bonuspressx (All Versions) - Cross-Site Scripting
mediumThe Bonuspressx plugin for WordPress is vulnerable to Cross-Site Scripting via the 'n' parameter in the 'ar_submit.php' file due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- May 12, 2014