Plugins List <= 2.5 - Authenticated (Author+) Stored Cross-Site Scripting via replace_plugin_list_tags
mediumThe Plugins List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the replace_plugin_list_tags function in versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with author-level access or higher to inject a...
- CVSS:
- 6.4
- Affected:
- up to 2.5
- Fixed in:
- 2.5.1
- Disclosed:
- Apr 28, 2023