Lazyest Backup < 0.2.2 - Reflected Cross-Site Scripting
mediumThe Lazyest Backup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'xml_or_all' parameter found in the lazyest-backup.php file in versions up to 0.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 6.1
- Affected:
- up to 0.2.2
- Fixed in:
- 0.2.2
- Disclosed:
- Dec 5, 2011