Shop Page WP <= 1.2.7 - Authenticated Cross-Site Scripting
mediumThe Shop Page WP WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Nov 1, 2021