1 results (0.002 seconds)

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1

The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. El plugin de WordPress WPFront Scroll Top versiones anteriores a 2.0.6.07225, no sanea ni escapa de su configuración de ALT de imagen antes de emitirla en atributos, conllevando a un problema de tipo Cross-Site Scripting Almacenado y Autenticado incluso cuando la capacidad unfiltered_html no está permitida. The WPFront Scroll Top WordPress plugin before 2.0.5 does not sanitise or escape its Image ALT setting before outputting it attributes, leading to an Authenticated Stored Cross-Site Scripting issues even when the unfiltered_html capability is disallowed. • https://wpscan.com/vulnerability/b25af0e1-392f-4305-ad44-50e64ef3dbdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •