User Registration, Login & Landing Pages <= 1.2.7 - Admin+ Stored Cross-Site Scripting
mediumThe User Registration, Login & Landing Pages WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the loader_text parameter found in the ~/includes/templates/landing-page.php file which allows attackers with administrative user access to inject arbitrary web scripts, in version...
- CVSS:
- 4.8
- Affected:
- up to 1.2.7
- Fix:
- No patched version reported
- Disclosed:
- Jan 18, 2022