WordPress Vulnerabilities
WP < 6.0.2 - Reflected Cross-Site Scripting
Description
Plugin's deactivation and deletion error messages are not escaped when output in the plugins screen, which could lead to Reflected Cross-Site Scripting
Affects WordPress
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Khalilov Moe
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-08-30 (about 3 years ago)
Added
2022-08-30 (about 3 years ago)
Last Updated
2022-08-30 (about 3 years ago)