Codup Read Only Admin <= 1.1.1.7 - Cross Site Scripting
mediumThe plugin Codup Read Only Admin for WordPress is vulnerable to Cross-Site Scripting via the read_only_admin parameter in the save_user_meta function in versions up to and including 1.1.1.7 due to insufficient sanitization. This makes it possible to attackers to inject arbitrary web scripts in pages that will execute w...
- CVSS:
- 6.4
- Affected:
- up to 1.1.1.7
- Fixed in:
- 1.1.1.8
- Disclosed:
- May 25, 2022