plugin

Page Scroll To Id Vulnerabilities

2 known security issues reported for the Page Scroll To Id WordPress plugin. Most recent disclosed Feb 16, 2024.

2 medium

Running Page Scroll To Id on your site? Check whether your installed version is affected.

Scan your site free

Page scroll to id <= 1.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Page scroll to id plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.7.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-le...

CVSS:
6.4
Affected:
up to 1.7.8
Fixed in:
1.7.9
Disclosed:
Feb 16, 2024

CVE-2024-1445 on NVD →

Page scroll to id <= 1.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Page scroll to id plugin for WordPress is vulnerable to Stored Cross-Site Scripting via one of its shortcode attributes in versions up to, and including, 1.7.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above...

CVSS:
6.4
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Dec 21, 2022

CVE-2022-4449 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database