CSS Hero <= 4.0.3 - Reflected Cross-Site Scripting
mediumThe CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affe...
- CVSS:
- 6.1
- Affected:
- up to 4.03
- Fixed in:
- 4.07
- Disclosed:
- Dec 2, 2019