WordPress Plugin Vulnerabilities

Export All URLs < 4.2 - Editor+ Stored Cross-Site Scripting

Description

The plugin does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Stored Cross-Site Scripting attacks

Affects Plugins

Fixed in 4.2

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Kim Jong Min
Verified
No

Timeline

Publicly Published
2022-05-27 (about 3 years ago)
Added
2022-06-16 (about 3 years ago)
Last Updated
2023-03-16 (about 3 years ago)

Other