Storefront Footer Text <= 1.0.1 - Authenticated (Admin+) Stored Cross-Site Scripting
mediumThe Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 1.0.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 11, 2021