The plugin does not escape some generated URLs before outputting them back in href attributes of admin dashboard pages, leading to Reflected Cross-Site Scripting
- Completely reset the site using the plugin - Visit https://example.com/wp-admin/tools.php?page=advanced_wp_reset&"><script>alert(1)</script>
ZhongFu Su(JrXnm) of WuHan University
ZhongFu Su(JrXnm) of WuHan University
Yes
2022-07-05 (about 1 months ago)
2022-07-05 (about 1 months ago)
2022-07-05 (about 1 months ago)