Lucene search

K
wpvulndbWpvulndbWPVDB-ID:5D24AB5A-084E-4A25-ADB8-2497CC6C8C89
HistoryJul 27, 2022 - 12:00 a.m.

GS Testimonial Slider <= 1.9.1 - Author+ Stored Cross-Site Scripting

2022-07-2700:00:00
wpscan.com
14
plugin
stored cross-site scripting
low-privileged users

EPSS

0.001

Percentile

19.4%

The plugin does not sanitise and escape some parameters, which could allow users with a role as low as author to perform Stored Cross-Site Scripting attacks

EPSS

0.001

Percentile

19.4%

Related for WPVDB-ID:5D24AB5A-084E-4A25-ADB8-2497CC6C8C89