post highlights 2.0 - 2.6 - Cross-Site Scripting
mediumCross-site scripting (XSS) vulnerability in the post highlights plugin versions 2.0 through 2.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the txt parameter in a headline action to ajax/ph_save.php.
- CVSS:
- 6.1
- Affected:
- 2.0 – 2.6
- Fixed in:
- 2.6.1
- Disclosed:
- Nov 3, 2014