Text Hover <= 4.1 - Admin+ Stored Cross-Site Scripting
mediumThe Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 4.1
- Fixed in:
- 4.2
- Disclosed:
- Apr 9, 2022