Maintenance <= 4.02 - Authenticated Stored Cross-Site Scripting
mediumThe Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend
- CVSS:
- 4.8
- Affected:
- up to 4.03
- Fixed in:
- 4.03
- Disclosed:
- Jul 21, 2021