WordPress Plugin Vulnerabilities

Comment Engine Pro <= 1.0 - Editor+ Stored Cross-Site Scripting

Description

The plugin does not sanitise and escape some parameters, allowing high privilege users such as editor (and above) to perform Stored Cross-Site Scripting attacks

Affects Plugins

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
John Castro
Verified
No

Timeline

Publicly Published
2021-12-13 (about 2 years ago)
Added
2021-12-13 (about 2 years ago)
Last Updated
2022-04-11 (about 2 years ago)

Other