1 results (0.002 seconds)

CVSS: 6.4EPSS: 0%CPEs: 20EXPL: 1

21 Feb 2023 — The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The Smart Logo Showcase Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.1.9 due to insufficient input ... • https://wpscan.com/vulnerability/cdcd3c2c-cb29-4b21-8d3d-7eafbc1d3098 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •