Ultimate NoFollow <= 1.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
mediumThe Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, allowing users with a role as low as contributor to perform Cross-Site Scripting attacks
- CVSS:
- 5.4
- Affected:
- up to 1.4.8
- Fix:
- No patched version reported
- Disclosed:
- Nov 15, 2021