Share and Follow <= 1.80.3 - Cross-Site Scripting
highCross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the CDN API Key (cnd-key) in a share-and-follow-menu page to wp-admin/admin.php.
- CVSS:
- 7.2
- Affected:
- up to 1.80.3
- Fixed in:
- 1.80.4
- Disclosed:
- May 21, 2012