1 results (0.001 seconds)
CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1
CVE-2022-0876 – Social comments by WpDevArt < 2.5.0 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-0876
The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when unfiltered_html is disallowed El plugin Social comments by WpDevArt de WordPress versiones anteriores a 2.5.0 no sanea ni escapa de su configuración, permitiendo a usuarios con privilegios elevados, como los administradores, llevar a cabo ataques de tipo cross-Site Scripting incluso cuando unfiltered_html no está permitido • https://wpscan.com/vulnerability/73be6e92-ea37-4416-977d-52ee2afa022a • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •