WordPress File Monitor <= 2.3.3 - Authenticated Stored Cross-Site Scripting
mediumThe WordPress File Monitor plugin is vulnerable to Cross-Site Scripting in versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with high privileges to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 5.5
- Affected:
- up to 2.3.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 22, 2016