The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
1. In the plugin's settings, enter the payload "><script>alert(1)</script> in the event_name field. 2. Reload the page and see the XSS.
Ilyase Dehy and Aymane Mazguiti
Ilyase Dehy and Aymane Mazguiti
Yes
2023-05-12 (about 4 months ago)
2023-05-12 (about 4 months ago)
2023-05-12 (about 4 months ago)