CVE-2022-1093 – WP Meta SEO < 4.4.7 - Admin+ Stored Cross-Site Scripting via breadcrumbs
https://notcve.org/view.php?id=CVE-2022-1093
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed. El plugin WP Meta SEO de WordPress versiones anteriores a 4.4.7, no sanea ni escapa del separador breadcrumb antes de enviarlo a la página, lo que permite a un usuario con altos privilegios, como un administrador, inyectar javascript arbitrario en la página incluso cuando el html sin filtrar no está permitido • https://wpscan.com/vulnerability/57017050-811e-474d-8256-33d19d4c0553 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •