The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.
Insert the following shortcode in a post: [wp_show_posts id='1' settings='inner_wrapper=div+onmouseover=alert(1)']
Lana Codes
Lana Codes
Yes
2022-12-21 (about 1 months ago)
2022-12-21 (about 1 months ago)
2022-12-21 (about 1 months ago)