i2 Pros & Cons <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
mediumThe i2 Pros & Cons is vulnerable to stored Cross-Site Scripting in versions up to, and including, 1.3.1, via the 'i2_pros_and_cons' shortcode. This makes it possible for authenticated attackers with contributor-level permissions or above to inject arbitrary web scripts in pages that will execute whenever a user accesse...
- CVSS:
- 6.4
- Affected:
- up to 1.3.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 13, 2023