WP Header Images <= 2.0.0 - Reflected Cross-Site Scripting
mediumThe WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.1
- Disclosed:
- Oct 11, 2021