The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/3d144e1c-a1f4-4c5a-93e2-4296a96d4ba2/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-03 06:15
Updated : 2024-07-12 16:11
NVD link : CVE-2024-2375
Mitre link : CVE-2024-2375
CVE.ORG link : CVE-2024-2375
JSON object : View
Products Affected
2code
- wpqa_builder
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')