My Link Order <= 4.3 - Authenticated Cross-Site Scripting
mediumThe My Link Order plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cats' & 'hdnCatID' parameters in versions up to, and including, 4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will exec...
- CVSS:
- 5.5
- Affected:
- up to 4.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 23, 2015