My Page Order <= 4.3 - Cross-Site Request Forgery to Cross-Site Scripting
highThe My Page Order plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting via the ‘pages' and 'hdnParentID’ parameters in versions up to, and including, 4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject a...
- CVSS:
- 8.8
- Affected:
- up to 4.3
- Fixed in:
- 4.4
- Disclosed:
- Nov 21, 2015