Social comments by WpDevArt <= 2.4.9 - Admin+ Stored Cross-Site Scripting
mediumThe Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed
- CVSS:
- 5.5
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- Apr 9, 2022