1 results (0.002 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). El complemento Login with Cognito de WordPress hasta la versión 1.4.8 no sanitiza ni escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar cross-site scripting almacenado incluso cuando la capacidad unfiltered_html no está permitida (por ejemplo, en la configuración de múltiples sitios). The Login with Cognito plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.  • https://wpscan.com/vulnerability/ac2e3fea-e1e6-4d90-9945-d8434a00a3cf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •