Wishful Blog <= 2.0.1 & Raise Mag <= 1.0.7 - Unauthenticated Cross-Site Scripting
mediumThe Wishful Blog theme, versions up to and including 2.0.1, and Raise Mag theme, versions up to and including 1.0.7, for WordPress are vulnerable to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 2.0.1
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2023