CoolClock <= 4.3.4 - Authenticated Stored Cross-Site Scripting
mediumThe CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks
- CVSS:
- 5.4
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.5
- Disclosed:
- Aug 30, 2021