Forum
Forum-Breadcrumbs - Du bist hier:ForumOffenes Forum: Security AdvisoriesCVE-2022-3135 - SEO Smart Links W …
CVE-2022-3135 - SEO Smart Links WordPress plugin
Zitat von MITs Forum am 26. September 2022, 0:00 UhrThe SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
References
https://wpscan.com/vulnerability/3505481d-141a-4516-bdbb-d4dad4e1eb01
The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
References
https://wpscan.com/vulnerability/3505481d-141a-4516-bdbb-d4dad4e1eb01
Anklicken für Daumen nach unten.0Anklicken für Daumen nach oben.0