1 results (0.002 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed El plugin Social comments by WpDevArt de WordPress versiones anteriores a 2.5.0 no sanea ni escapa de su configuración, permitiendo a usuarios con privilegios elevados, como los administradores, llevar a cabo ataques de tipo cross-Site Scripting incluso cuando unfiltered_html no está permitido • https://wpscan.com/vulnerability/73be6e92-ea37-4416-977d-52ee2afa022a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •