Dropdown and scrollable Text <= 2.0 - Cross-Site Scripting
medium
The plugin Dropdown and scrollable Text for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 5.4
- Affected:
- up to 2.0
- Fixed in:
- 2.1
- Disclosed:
- May 25, 2022
Dropdown and scrollable Text <= 2.0 Reflected Cross-Site Scripting
medium
The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.
- CVSS:
- 6.1
- Affected:
- up to 2.0
- Fixed in:
- 2.1
- Disclosed:
- Sep 9, 2021
CVE-2021-38353 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database