1 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed El plugin Custom Share Buttons with Floating Sidebar de WordPress versiones anteriores a 4.2, no sanea ni escapa de algunas de sus configuraciones, lo que podría permitir a usuarios muy privilegiados, como los administradores, llevar a cabo ataques de tipo Cross-Site Scripting Almacenado cuando la capacidad unfiltered_html no está permitida The Custom Share Buttons with Floating Sidebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 4.1 via several parameters. This makes it possible for authenticated attackers to inject arbitrary web scripts that may execute when a victim accesses a page containing the malicious payload. • https://wpscan.com/vulnerability/79a532e9-bc6e-4722-8d67-9c15720d06a6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •