1 results (0.002 seconds)

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 1

20 Oct 2022 — The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. El complemento Testimonials WordPress anterior a 2.7 y el complemento super-testimonial-pro de WordPress anterior a 1.0.8 no sanitiza y escapan de su configuración, lo que permite a usuarios con altos privilegios, como el administrad... • https://wpscan.com/vulnerability/ab3b0052-1a74-4ba3-b6d2-78cfe56029db • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •