Slideoptinprox (Unspecified Version) - Cross-Site Scripting
mediumThe Slideoptinprox plugin for WordPress is vulnerable to Cross-Site Scripting via the 'id' parameter in the 'ar_submit.php' file due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Jan 9, 2015