Light Messages <= 1.0 - Authenticated (Admin+) Cross-Site Scripting
mediumThe Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them (even with the unfiltered_html disallowed). As a result, an attacker could make a logged in admin update the settings to arbitrary values, and set a Cross-Site Scripting p...
- CVSS:
- 6.1
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 19, 2021