WordPress Plugin Vulnerabilities
Minimal Coming Soon – Coming Soon Page < 2.35 - Multiple Authenticated Stored XSS
Description
The plugin does not sanitize or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them, which will be triggered in the backend.
A
Proof of Concept
Affects Plugins
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-05-23 (about 3 years ago)
Added
2022-05-23 (about 3 years ago)
Last Updated
2022-05-23 (about 3 years ago)