WordPress Plugin Vulnerabilities

Custom Permalinks <= 1.1 - Cross-Site Scripting (XSS)

Description

User controllable input in the admin page of Custom Permalinks gets output without any escaping.

Proof of Concept

Affects Plugins

Fixed in 1.2

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Karim El Ouerghemmi
Submitter website
Verified
No

Timeline

Publicly Published
2018-02-22 (about 8 years ago)
Added
2018-02-25 (about 8 years ago)
Last Updated
2018-02-25 (about 8 years ago)

Other