Logo Carousel < 1.7.2 - Stored Cross-Site Scripting
mediumThe Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings' tab or tab_flags_order parameters in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authent...
- CVSS:
- 6.5
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.2
- Disclosed:
- Nov 22, 2021