WP-CommentNavi <= 1.12.1 - Authenticated (Admin+) Stored Cross-Site Scripting
mediumThe WP-CommentNavi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the navi options 'pages_text', 'current_text', 'page_text', 'first_text', 'last_text', 'next_text', 'prev_text', 'dotright_text', and 'num_pages', in versions up to, and including, 1.12.1 due to insufficient input sanitization and...
- CVSS:
- 5.5
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.2
- Disclosed:
- Jan 17, 2023