WP-Banners-Lite 1.29, 1.31, 1.40 - Cross-Site Scripting
mediumThe WP-Banners-Lite plugin for WordPress is vulnerable to Cross-Site Scripting via the 'cid' variable in versions 1.29, 1.31, and 1.40 due to insufficient input sanitization and output escaping. This makes it possible for unauthorized attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- 1.29 – 1.29, 1.31 – 1.31, 1.40 – 1.40
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2014